Search

Find a vulnerability

Search criteria

    51 vulnerabilities found for ontap by netapp

    CVE-2026-22049 (GCVE-0-2026-22049)

    Vulnerability from nvd – Published: 2026-07-22 18:52 – Updated: 2026-07-25 03:55
    VLAI
    Summary
    ONTAP versions 9.16.1 and higher with WebAuthn multi-factor authentication (MFA) configured are susceptible to a vulnerability related to the Relying Party ID which when successfully exploited could allow an attacker with valid credentials to bypass MFA.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-07-24 00:00 UTC
    CWE
    • 288
    • CWE-288 - Authentication Bypass Using an Alternate Path or Channel
    Impacted products
    Vendor Product Version
    NETAPP ONTAP 9 Affected: 9.16.1 , < 9.19.1 (custom)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-22049",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-07-24T00:00:00+00:00",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-288",
                    "description": "CWE-288 Authentication Bypass Using an Alternate Path or Channel",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-07-25T03:55:53.307Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "ONTAP 9",
              "vendor": "NETAPP",
              "versions": [
                {
                  "lessThan": "9.19.1",
                  "status": "affected",
                  "version": "9.16.1",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "ONTAP versions 9.16.1 and higher with WebAuthn multi-factor authentication (MFA) configured are susceptible to a vulnerability related to the Relying Party ID which when successfully exploited could allow an attacker with valid credentials to bypass MFA."
                }
              ],
              "value": "ONTAP versions 9.16.1 and higher with WebAuthn multi-factor authentication (MFA) configured are susceptible to a vulnerability related to the Relying Party ID which when successfully exploited could allow an attacker with valid credentials to bypass MFA."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 8.7,
                "baseSeverity": "HIGH",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "LOW",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "288",
                  "lang": "en"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-07-22T18:52:14.069Z",
            "orgId": "11fdca00-0482-4c88-a206-37f9c182c87d",
            "shortName": "netapp"
          },
          "references": [
            {
              "url": "https://security.netapp.com/advisory/NTAP-20260722-0001/"
            }
          ],
          "source": {
            "advisory": "NTAP-20260722-0001",
            "discovery": "UNKNOWN"
          },
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "11fdca00-0482-4c88-a206-37f9c182c87d",
        "assignerShortName": "netapp",
        "cveId": "CVE-2026-22049",
        "datePublished": "2026-07-22T18:52:14.069Z",
        "dateReserved": "2026-01-05T22:47:18.701Z",
        "dateUpdated": "2026-07-25T03:55:53.307Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-22052 (GCVE-0-2026-22052)

    Vulnerability from nvd – Published: 2026-03-04 23:22 – Updated: 2026-03-06 18:25
    VLAI
    Summary
    ONTAP versions 9.12.1 and higher with S3 NAS buckets are susceptible to an information disclosure vulnerability. Successful exploit could allow an authenticated attacker to view a listing of the contents in a directory for which they lack permission.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-03-06 18:25 UTC
    CWE
    • 209
    • CWE-209 - Generation of Error Message Containing Sensitive Information
    Impacted products
    Vendor Product Version
    NETAPP ONTAP 9 Affected: 9.12.1 and higher
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-22052",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-03-06T18:25:10.691167Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-209",
                    "description": "CWE-209 Generation of Error Message Containing Sensitive Information",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-03-06T18:25:24.078Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "ONTAP 9",
              "vendor": "NETAPP",
              "versions": [
                {
                  "status": "affected",
                  "version": "9.12.1 and higher"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "ONTAP versions 9.12.1 and higher with S3 NAS buckets are susceptible to an information disclosure vulnerability. Successful exploit could allow an authenticated attacker to view a listing of the contents in a directory for which they lack permission."
                }
              ],
              "value": "ONTAP versions 9.12.1 and higher with S3 NAS buckets are susceptible to an information disclosure vulnerability. Successful exploit could allow an authenticated attacker to view a listing of the contents in a directory for which they lack permission."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "LOW",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "LOW",
                "vulnIntegrityImpact": "NONE",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "209",
                  "lang": "en"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-03-04T23:22:22.957Z",
            "orgId": "11fdca00-0482-4c88-a206-37f9c182c87d",
            "shortName": "netapp"
          },
          "references": [
            {
              "url": "https://security.netapp.com/advisory/NTAP-20260304-0001"
            }
          ],
          "source": {
            "advisory": "NTAP-20260304-0001",
            "discovery": "UNKNOWN"
          },
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "11fdca00-0482-4c88-a206-37f9c182c87d",
        "assignerShortName": "netapp",
        "cveId": "CVE-2026-22052",
        "datePublished": "2026-03-04T23:22:22.957Z",
        "dateReserved": "2026-01-05T22:47:18.701Z",
        "dateUpdated": "2026-03-06T18:25:24.078Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-22050 (GCVE-0-2026-22050)

    Vulnerability from nvd – Published: 2026-01-12 17:15 – Updated: 2026-01-13 17:30
    VLAI
    Summary
    ONTAP versions 9.16.1 prior to 9.16.1P9 and 9.17.1 prior to 9.17.1P2 with snapshot locking enabled are susceptible to a vulnerability which could allow a privileged remote attacker to set the snapshot expiry time to none.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-01-12 17:36 UTC
    CWE
    • 639
    • CWE-639 - Authorization Bypass Through User-Controlled Key
    Impacted products
    Vendor Product Version
    NETAPP ONTAP 9 Affected: 9.16.1 , < 9.16.1P9 (custom)
    Affected: 9.17.1 , < 9.17.1P2 (custom)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-22050",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-01-12T17:36:52.693542Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-639",
                    "description": "CWE-639 Authorization Bypass Through User-Controlled Key",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-01-13T17:30:51.952Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "ONTAP 9",
              "vendor": "NETAPP",
              "versions": [
                {
                  "lessThan": "9.16.1P9",
                  "status": "affected",
                  "version": "9.16.1",
                  "versionType": "custom"
                },
                {
                  "lessThan": "9.17.1P2",
                  "status": "affected",
                  "version": "9.17.1",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "ONTAP versions 9.16.1 prior to 9.16.1P9 and 9.17.1 prior to 9.17.1P2 with snapshot locking enabled are susceptible to a vulnerability which could allow a privileged remote attacker to set the snapshot expiry time to none."
                }
              ],
              "value": "ONTAP versions 9.16.1 prior to 9.16.1P9 and 9.17.1 prior to 9.17.1P2 with snapshot locking enabled are susceptible to a vulnerability which could allow a privileged remote attacker to set the snapshot expiry time to none."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 6.9,
                "baseSeverity": "MEDIUM",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "HIGH",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "NONE",
                "vulnIntegrityImpact": "HIGH",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "639",
                  "lang": "en"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-01-12T17:15:07.484Z",
            "orgId": "11fdca00-0482-4c88-a206-37f9c182c87d",
            "shortName": "netapp"
          },
          "references": [
            {
              "url": "https://security.netapp.com/advisory/NTAP-20260112-0001"
            }
          ],
          "source": {
            "advisory": "NTAP-20260112-0001",
            "discovery": "EXTERNAL"
          },
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "11fdca00-0482-4c88-a206-37f9c182c87d",
        "assignerShortName": "netapp",
        "cveId": "CVE-2026-22050",
        "datePublished": "2026-01-12T17:15:07.484Z",
        "dateReserved": "2026-01-05T22:47:18.701Z",
        "dateUpdated": "2026-01-13T17:30:51.952Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2025-1861 (GCVE-0-2025-1861)

    Vulnerability from nvd – Published: 2025-03-30 05:57 – Updated: 2025-11-03 20:57
    VLAI
    Title
    Stream HTTP wrapper truncates redirect location to 1024 bytes
    Summary
    In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when parsing HTTP redirect in the response to an HTTP request, there is currently limit on the location value size caused by limited size of the location buffer to 1024. However as per RFC9110, the limit is recommended to be 8000. This may lead to incorrect URL truncation and redirecting to a wrong location.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-03-31 12:55 UTC
    CWE
    • CWE-131 - Incorrect Calculation of Buffer Size
    Impacted products
    Vendor Product Version
    PHP Group PHP Affected: 8.1.* , < 8.1.32 (semver)
    Affected: 8.2.* , < 8.2.28 (semver)
    Affected: 8.3.* , < 8.3.19 (semver)
    Affected: 8.4.* , < 8.4.5 (semver)
    Create a notification for this product.
    Date Public
    2025-03-23 17:44
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-1861",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-03-31T12:55:53.101020Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-03-31T12:56:00.966Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2025-11-03T20:57:13.769Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "url": "https://security.netapp.com/advisory/ntap-20250523-0005/"
              },
              {
                "url": "https://lists.debian.org/debian-lts-announce/2025/03/msg00014.html"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "affected",
              "product": "PHP",
              "vendor": "PHP Group",
              "versions": [
                {
                  "lessThan": "8.1.32",
                  "status": "affected",
                  "version": "8.1.*",
                  "versionType": "semver"
                },
                {
                  "lessThan": "8.2.28",
                  "status": "affected",
                  "version": "8.2.*",
                  "versionType": "semver"
                },
                {
                  "lessThan": "8.3.19",
                  "status": "affected",
                  "version": "8.3.*",
                  "versionType": "semver"
                },
                {
                  "lessThan": "8.4.5",
                  "status": "affected",
                  "version": "8.4.*",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "Jakub Zelenka"
            }
          ],
          "datePublic": "2025-03-23T17:44:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eIn PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when parsing HTTP redirect in the response to an HTTP request, there is currently limit on the location value size caused by limited size of the location buffer to 1024. However as per RFC9110\u003c/span\u003e\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003e, the limit is recommended to be 8000. This may lead to incorrect URL truncation and redirecting to a wrong location.\u0026nbsp;\u003c/span\u003e\u003cbr\u003e"
                }
              ],
              "value": "In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when parsing HTTP redirect in the response to an HTTP request, there is currently limit on the location value size caused by limited size of the location buffer to 1024. However as per RFC9110, the limit is recommended to be 8000. This may lead to incorrect URL truncation and redirecting to a wrong location."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-220",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-220 Client-Server Protocol Manipulation"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "PRESENT",
                "attackVector": "NETWORK",
                "baseScore": 6.3,
                "baseSeverity": "MEDIUM",
                "privilegesRequired": "NONE",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "LOW",
                "vulnIntegrityImpact": "NONE",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-131",
                  "description": "CWE-131 Incorrect Calculation of Buffer Size",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-03-30T05:57:57.894Z",
            "orgId": "dd77f84a-d19a-4638-8c3d-a322d820ed2b",
            "shortName": "php"
          },
          "references": [
            {
              "url": "https://github.com/php/php-src/security/advisories/GHSA-52jp-hrpf-2jff"
            }
          ],
          "source": {
            "advisory": "https://github.com/php/php-src/security/advisories/GHSA-52jp-hrp",
            "discovery": "INTERNAL"
          },
          "title": "Stream HTTP wrapper truncates redirect location to 1024 bytes",
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "dd77f84a-d19a-4638-8c3d-a322d820ed2b",
        "assignerShortName": "php",
        "cveId": "CVE-2025-1861",
        "datePublished": "2025-03-30T05:57:57.894Z",
        "dateReserved": "2025-03-03T04:47:51.192Z",
        "dateUpdated": "2025-11-03T20:57:13.769Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2025-1736 (GCVE-0-2025-1736)

    Vulnerability from nvd – Published: 2025-03-30 05:49 – Updated: 2025-11-03 20:57
    VLAI
    Title
    Stream HTTP wrapper header check might omit basic auth header
    Summary
    In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when user-supplied headers are sent, the insufficient validation of the end-of-line characters may prevent certain headers from being sent or lead to certain headers be misinterpreted.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-03-31 12:57 UTC
    CWE
    • CWE-20 - Improper Input Validation
    Impacted products
    Vendor Product Version
    PHP Group PHP Affected: 8.1.* , < 8.1.32 (semver)
    Affected: 8.2.* , < 8.2.28 (semver)
    Affected: 8.3.* , < 8.3.19 (semver)
    Affected: 8.4.* , < 8.4.5 (semver)
    Create a notification for this product.
    Date Public
    2025-03-23 17:43
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-1736",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-03-31T12:57:12.660404Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-03-31T12:57:22.517Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2025-11-03T20:57:10.963Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "url": "https://security.netapp.com/advisory/ntap-20250523-0006/"
              },
              {
                "url": "https://lists.debian.org/debian-lts-announce/2025/03/msg00014.html"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "affected",
              "product": "PHP",
              "vendor": "PHP Group",
              "versions": [
                {
                  "lessThan": "8.1.32",
                  "status": "affected",
                  "version": "8.1.*",
                  "versionType": "semver"
                },
                {
                  "lessThan": "8.2.28",
                  "status": "affected",
                  "version": "8.2.*",
                  "versionType": "semver"
                },
                {
                  "lessThan": "8.3.19",
                  "status": "affected",
                  "version": "8.3.*",
                  "versionType": "semver"
                },
                {
                  "lessThan": "8.4.5",
                  "status": "affected",
                  "version": "8.4.*",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "Jakub Zelenka"
            }
          ],
          "datePublic": "2025-03-23T17:43:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when user-supplied headers are sent, the insufficient validation of the end-of-line characters may prevent certain headers from being sent or lead to certain headers be misinterpreted.\u0026nbsp;"
                }
              ],
              "value": "In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when user-supplied headers are sent, the insufficient validation of the end-of-line characters may prevent certain headers from being sent or lead to certain headers be misinterpreted."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-33",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-33 HTTP Request Smuggling"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "HIGH",
                "attackRequirements": "PRESENT",
                "attackVector": "NETWORK",
                "baseScore": 6.3,
                "baseSeverity": "MEDIUM",
                "privilegesRequired": "NONE",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "LOW",
                "vulnIntegrityImpact": "NONE",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-20",
                  "description": "CWE-20 Improper Input Validation",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-03-30T05:49:14.551Z",
            "orgId": "dd77f84a-d19a-4638-8c3d-a322d820ed2b",
            "shortName": "php"
          },
          "references": [
            {
              "url": "https://github.com/php/php-src/security/advisories/GHSA-hgf5-96fm-v528"
            }
          ],
          "source": {
            "advisory": "https://github.com/php/php-src/security/advisories/GHSA-hgf5-96f",
            "discovery": "INTERNAL"
          },
          "title": "Stream HTTP wrapper header check might omit basic auth header",
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "dd77f84a-d19a-4638-8c3d-a322d820ed2b",
        "assignerShortName": "php",
        "cveId": "CVE-2025-1736",
        "datePublished": "2025-03-30T05:49:14.551Z",
        "dateReserved": "2025-02-27T04:07:07.942Z",
        "dateUpdated": "2025-11-03T20:57:10.963Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2025-1734 (GCVE-0-2025-1734)

    Vulnerability from nvd – Published: 2025-03-30 05:43 – Updated: 2025-11-03 20:57
    VLAI
    Title
    Streams HTTP wrapper does not fail for headers with invalid name and no colon
    Summary
    In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when receiving headers from HTTP server, the headers missing a colon (:) are treated as valid headers even though they are not. This may confuse applications into accepting invalid headers.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-03-31 14:21 UTC
    CWE
    • CWE-20 - Improper Input Validation
    Impacted products
    Vendor Product Version
    PHP Group PHP Affected: 8.1.* , < 8.1.32 (semver)
    Affected: 8.2.* , < 8.2.28 (semver)
    Affected: 8.3.* , < 8.3.19 (semver)
    Affected: 8.4.* , < 8.4.5 (semver)
    Create a notification for this product.
    Date Public
    2025-03-23 17:43
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-1734",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-03-31T14:21:51.418644Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-04-01T14:37:34.371Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2025-11-03T20:57:09.506Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "url": "https://security.netapp.com/advisory/ntap-20250523-0009/"
              },
              {
                "url": "https://lists.debian.org/debian-lts-announce/2025/03/msg00014.html"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "affected",
              "product": "PHP",
              "vendor": "PHP Group",
              "versions": [
                {
                  "lessThan": "8.1.32",
                  "status": "affected",
                  "version": "8.1.*",
                  "versionType": "semver"
                },
                {
                  "lessThan": "8.2.28",
                  "status": "affected",
                  "version": "8.2.*",
                  "versionType": "semver"
                },
                {
                  "lessThan": "8.3.19",
                  "status": "affected",
                  "version": "8.3.*",
                  "versionType": "semver"
                },
                {
                  "lessThan": "8.4.5",
                  "status": "affected",
                  "version": "8.4.*",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "Jakub Zelenka"
            }
          ],
          "datePublic": "2025-03-23T17:43:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when receiving headers from HTTP server, the headers missing a colon (:) are treated as valid headers even though they are not. This may confuse applications into accepting invalid headers."
                }
              ],
              "value": "In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when receiving headers from HTTP server, the headers missing a colon (:) are treated as valid headers even though they are not. This may confuse applications into accepting invalid headers."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-273",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-273 HTTP Response Smuggling"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "HIGH",
                "attackRequirements": "PRESENT",
                "attackVector": "NETWORK",
                "baseScore": 6.3,
                "baseSeverity": "MEDIUM",
                "privilegesRequired": "NONE",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "LOW",
                "vulnIntegrityImpact": "NONE",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-20",
                  "description": "CWE-20 Improper Input Validation",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-03-30T05:43:35.771Z",
            "orgId": "dd77f84a-d19a-4638-8c3d-a322d820ed2b",
            "shortName": "php"
          },
          "references": [
            {
              "url": "https://github.com/php/php-src/security/advisories/GHSA-pcmh-g36c-qc44"
            }
          ],
          "source": {
            "advisory": "https://github.com/php/php-src/security/advisories/GHSA-pcmh-g36",
            "discovery": "INTERNAL"
          },
          "title": "Streams HTTP wrapper does not fail for headers with invalid name and no colon",
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "dd77f84a-d19a-4638-8c3d-a322d820ed2b",
        "assignerShortName": "php",
        "cveId": "CVE-2025-1734",
        "datePublished": "2025-03-30T05:43:35.771Z",
        "dateReserved": "2025-02-27T04:03:59.544Z",
        "dateUpdated": "2025-11-03T20:57:09.506Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2025-24928 (GCVE-0-2025-24928)

    Vulnerability from nvd – Published: 2025-02-18 00:00 – Updated: 2026-02-26 19:08
    VLAI
    Summary
    libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a stack-based buffer overflow in xmlSnprintfElements in valid.c. To exploit this, DTD validation must occur for an untrusted document or untrusted DTD. NOTE: this is similar to CVE-2017-9047.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-07-23 03:55 UTC
    CWE
    • CWE-121 - Stack-based Buffer Overflow
    Impacted products
    Vendor Product Version
    xmlsoft libxml2 Affected: 0 , < 2.12.10 (semver)
    Affected: 2.13.0 , < 2.13.6 (semver)
        cpe:2.3:a:xmlsoft:libxml2:*:*:*:*:*:*:*:*
        cpe:2.3:a:xmlsoft:libxml2:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-24928",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-07-23T03:55:31.854089Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-02-26T19:08:48.412Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2025-11-03T21:12:47.571Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "url": "https://security.netapp.com/advisory/ntap-20250321-0006/"
              },
              {
                "url": "https://lists.debian.org/debian-lts-announce/2025/02/msg00028.html"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "libxml2",
              "vendor": "xmlsoft",
              "versions": [
                {
                  "lessThan": "2.12.10",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "2.13.6",
                  "status": "affected",
                  "version": "2.13.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:xmlsoft:libxml2:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "2.12.10",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:xmlsoft:libxml2:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "2.13.6",
                      "versionStartIncluding": "2.13.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a stack-based buffer overflow in xmlSnprintfElements in valid.c. To exploit this, DTD validation must occur for an untrusted document or untrusted DTD. NOTE: this is similar to CVE-2017-9047."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 7.8,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-121",
                  "description": "CWE-121 Stack-based Buffer Overflow",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-02-18T22:20:43.285Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "url": "https://gitlab.gnome.org/GNOME/libxml2/-/issues/847"
            },
            {
              "url": "https://issues.oss-fuzz.com/issues/392687022"
            }
          ],
          "x_generator": {
            "engine": "enrichogram 0.0.1"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2025-24928",
        "datePublished": "2025-02-18T00:00:00.000Z",
        "dateReserved": "2025-01-28T00:00:00.000Z",
        "dateUpdated": "2026-02-26T19:08:48.412Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2024-56171 (GCVE-0-2024-56171)

    Vulnerability from nvd – Published: 2025-02-18 00:00 – Updated: 2025-11-03 20:49
    VLAI
    Summary
    libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a use-after-free in xmlSchemaIDCFillNodeTables and xmlSchemaBubbleIDCNodeTables in xmlschemas.c. To exploit this, a crafted XML document must be validated against an XML schema with certain identity constraints, or a crafted XML schema must be used.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-02-19 16:26 UTC
    CWE
    Impacted products
    Vendor Product Version
    xmlsoft libxml2 Affected: 0 , < 2.12.10 (semver)
    Affected: 2.13.0 , < 2.13.6 (semver)
        cpe:2.3:a:xmlsoft:libxml2:*:*:*:*:*:*:*:*
        cpe:2.3:a:xmlsoft:libxml2:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-56171",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-02-19T16:26:31.484719Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-02-19T16:26:41.297Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2025-11-03T20:49:05.224Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "url": "https://security.netapp.com/advisory/ntap-20250328-0010/"
              },
              {
                "url": "http://seclists.org/fulldisclosure/2025/Apr/13"
              },
              {
                "url": "http://seclists.org/fulldisclosure/2025/Apr/10"
              },
              {
                "url": "http://seclists.org/fulldisclosure/2025/Apr/9"
              },
              {
                "url": "http://seclists.org/fulldisclosure/2025/Apr/8"
              },
              {
                "url": "http://seclists.org/fulldisclosure/2025/Apr/5"
              },
              {
                "url": "http://seclists.org/fulldisclosure/2025/Apr/4"
              },
              {
                "url": "http://seclists.org/fulldisclosure/2025/Apr/12"
              },
              {
                "url": "http://seclists.org/fulldisclosure/2025/Apr/11"
              },
              {
                "url": "https://lists.debian.org/debian-lts-announce/2025/02/msg00028.html"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "libxml2",
              "vendor": "xmlsoft",
              "versions": [
                {
                  "lessThan": "2.12.10",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "2.13.6",
                  "status": "affected",
                  "version": "2.13.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:xmlsoft:libxml2:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "2.12.10",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:xmlsoft:libxml2:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "2.13.6",
                      "versionStartIncluding": "2.13.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a use-after-free in xmlSchemaIDCFillNodeTables and xmlSchemaBubbleIDCNodeTables in xmlschemas.c. To exploit this, a crafted XML document must be validated against an XML schema with certain identity constraints, or a crafted XML schema must be used."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 7.8,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-416",
                  "description": "CWE-416 Use After Free",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-02-18T22:10:20.934Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "url": "https://gitlab.gnome.org/GNOME/libxml2/-/issues/828"
            }
          ],
          "x_generator": {
            "engine": "enrichogram 0.0.1"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2024-56171",
        "datePublished": "2025-02-18T00:00:00.000Z",
        "dateReserved": "2024-12-18T00:00:00.000Z",
        "dateUpdated": "2025-11-03T20:49:05.224Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2025-26465 (GCVE-0-2025-26465)

    Vulnerability from nvd – Published: 2025-02-18 18:27 – Updated: 2026-09-02 01:41
    VLAI
    Title
    Openssh: machine-in-the-middle attack if verifyhostkeydns is enabled
    Summary
    A vulnerability was found in OpenSSH when the VerifyHostKeyDNS option is enabled. A machine-in-the-middle attack can be performed by a malicious machine impersonating a legit server. This issue occurs due to how OpenSSH mishandles error codes in specific conditions when verifying the host key. For an attack to be considered successful, the attacker needs to manage to exhaust the client's memory resource first, turning the attack complexity high.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-02-19 15:02 UTC
    CWE
    • CWE-390 - Detection of Error Condition Without Action
    References
    URL Tags
    https://access.redhat.com/errata/RHSA-2025:16823 vendor-advisoryx_refsource_REDHAT
    https://access.redhat.com/errata/RHSA-2025:3837 vendor-advisoryx_refsource_REDHAT
    https://access.redhat.com/errata/RHSA-2025:6993 vendor-advisoryx_refsource_REDHAT
    https://access.redhat.com/errata/RHSA-2025:8385 vendor-advisoryx_refsource_REDHAT
    https://access.redhat.com/security/cve/CVE-2025-26465 vdb-entryx_refsource_REDHAT
    https://access.redhat.com/solutions/7109879
    https://bugzilla.redhat.com/show_bug.cgi?id=2344780 issue-trackingx_refsource_REDHAT
    https://seclists.org/oss-sec/2025/q1/144
    https://lists.debian.org/debian-lts-announce/2025…
    https://www.openwall.com/lists/oss-security/2025/…
    https://www.openwall.com/lists/oss-security/2025/…
    https://www.theregister.com/2025/02/18/openssh_vu…
    https://bugzilla.suse.com/show_bug.cgi?id=1237040
    https://security-tracker.debian.org/tracker/CVE-2…
    https://ftp.openbsd.org/pub/OpenBSD/patches/7.6/c…
    https://ubuntu.com/security/CVE-2025-26465
    https://www.openssh.com/releasenotes.html#9.9p2
    https://blog.qualys.com/vulnerabilities-threat-re…
    https://lists.mindrot.org/pipermail/openssh-unix-…
    https://security.netapp.com/advisory/ntap-2025022…
    https://www.vicarius.io/vsociety/posts/cve-2025-2…
    https://www.vicarius.io/vsociety/posts/cve-2025-2…
    http://seclists.org/fulldisclosure/2025/May/8
    http://seclists.org/fulldisclosure/2025/May/7
    http://seclists.org/fulldisclosure/2025/Feb/18
    https://cert-portal.siemens.com/productcert/html/…
    https://cert-portal.siemens.com/productcert/html/…
    Impacted products
    Vendor Product Version
    Affected: 6.8p1 , ≤ 9.9p1 (custom)
    Red Hat Red Hat Enterprise Linux 8 Unaffected: 0:8.0p1-26.el8_10 , < * (rpm)
        cpe:/a:redhat:enterprise_linux:8::appstream
        cpe:/o:redhat:enterprise_linux:8::baseos
    Create a notification for this product.
    Red Hat Red Hat Enterprise Linux 9 Unaffected: 0:8.7p1-45.el9 , < * (rpm)
        cpe:/a:redhat:enterprise_linux:9::appstream
        cpe:/o:redhat:enterprise_linux:9::baseos
    Create a notification for this product.
    Red Hat Red Hat Enterprise Linux 9.4 Extended Update Support Unaffected: 0:8.7p1-38.el9_4.5 , < * (rpm)
        cpe:/a:redhat:rhel_eus:9.4::appstream
        cpe:/o:redhat:rhel_eus:9.4::baseos
    Create a notification for this product.
    Red Hat Red Hat Discovery 1.14 Unaffected: 1.14.3-1748529279 , < * (rpm)
        cpe:/a:redhat:discovery:1.14::el9
    Create a notification for this product.
    Red Hat Red Hat Enterprise Linux 10     cpe:/o:redhat:enterprise_linux:10
    Create a notification for this product.
    Red Hat Red Hat Enterprise Linux 6     cpe:/o:redhat:enterprise_linux:6
    Create a notification for this product.
    Red Hat Red Hat Enterprise Linux 7     cpe:/o:redhat:enterprise_linux:7
    Create a notification for this product.
    Red Hat Red Hat OpenShift Container Platform 4     cpe:/a:redhat:openshift:4
    Create a notification for this product.
    Siemens SIDIS Secured SmartPlug Affected: 0 , < V7.26.0310 (custom)
    Create a notification for this product.
    Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP Affected: V3.1.5 , < * (custom)
    Create a notification for this product.
    Siemens SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP Affected: V3.1.5 , < * (custom)
    Create a notification for this product.
    Siemens SIPLUS S7-1500 CPU 1518-4 PN/DP MFP Affected: V3.1.5 , < * (custom)
    Create a notification for this product.
    Date Public
    2025-02-17 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2025-11-03T21:12:55.938Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "url": "https://lists.debian.org/debian-lts-announce/2025/02/msg00020.html"
              },
              {
                "url": "https://www.openwall.com/lists/oss-security/2025/02/18/1"
              },
              {
                "url": "https://www.openwall.com/lists/oss-security/2025/02/18/4"
              },
              {
                "url": "https://www.theregister.com/2025/02/18/openssh_vulnerabilities_mitm_dos/"
              },
              {
                "url": "https://bugzilla.suse.com/show_bug.cgi?id=1237040"
              },
              {
                "url": "https://security-tracker.debian.org/tracker/CVE-2025-26465"
              },
              {
                "url": "https://ftp.openbsd.org/pub/OpenBSD/patches/7.6/common/008_ssh.patch.sig"
              },
              {
                "url": "https://ubuntu.com/security/CVE-2025-26465"
              },
              {
                "url": "https://www.openssh.com/releasenotes.html#9.9p2"
              },
              {
                "url": "https://blog.qualys.com/vulnerabilities-threat-research/2025/02/18/qualys-tru-discovers-two-vulnerabilities-in-openssh-cve-2025-26465-cve-2025-26466"
              },
              {
                "url": "https://lists.mindrot.org/pipermail/openssh-unix-announce/2025-February/000161.html"
              },
              {
                "url": "https://security.netapp.com/advisory/ntap-20250228-0003/"
              },
              {
                "url": "https://www.vicarius.io/vsociety/posts/cve-2025-26465-detect-vulnerable-openssh"
              },
              {
                "url": "https://www.vicarius.io/vsociety/posts/cve-2025-26465-mitigate-vulnerable-openssh"
              },
              {
                "url": "http://seclists.org/fulldisclosure/2025/May/8"
              },
              {
                "url": "http://seclists.org/fulldisclosure/2025/May/7"
              },
              {
                "url": "http://seclists.org/fulldisclosure/2025/Feb/18"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-26465",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-02-19T15:02:09.369445Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-02-19T15:02:45.555Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "exploit"
                ],
                "url": "https://seclists.org/oss-sec/2025/q1/144"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          },
          {
            "affected": [
              {
                "defaultStatus": "unknown",
                "product": "SIDIS Secured SmartPlug",
                "vendor": "Siemens",
                "versions": [
                  {
                    "lessThan": "V7.26.0310",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "defaultStatus": "unknown",
                "product": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP",
                "vendor": "Siemens",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "V3.1.5",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "defaultStatus": "unknown",
                "product": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP",
                "vendor": "Siemens",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "V3.1.5",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "defaultStatus": "unknown",
                "product": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP",
                "vendor": "Siemens",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "V3.1.5",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "defaultStatus": "unknown",
                "product": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP",
                "vendor": "Siemens",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "V3.1.5",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "defaultStatus": "unknown",
                "product": "SIPLUS S7-1500 CPU 1518-4 PN/DP MFP",
                "vendor": "Siemens",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "V3.1.5",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-07-14T12:41:01.736Z",
              "orgId": "0b142b55-0307-4c5a-b3c9-f314f3fb7c5e",
              "shortName": "siemens-SADP"
            },
            "references": [
              {
                "url": "https://cert-portal.siemens.com/productcert/html/ssa-082556.html"
              },
              {
                "url": "https://cert-portal.siemens.com/productcert/html/ssa-585531.html"
              }
            ],
            "x_adpType": "supplier"
          }
        ],
        "cna": {
          "affected": [
            {
              "collectionURL": "https://www.openssh.com/",
              "defaultStatus": "unaffected",
              "packageName": "OpenSSH",
              "repo": "https://anongit.mindrot.org/openssh.git",
              "versions": [
                {
                  "lessThanOrEqual": "9.9p1",
                  "status": "affected",
                  "version": "6.8p1",
                  "versionType": "custom"
                }
              ]
            },
            {
              "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
              "cpes": [
                "cpe:/a:redhat:enterprise_linux:8::appstream",
                "cpe:/o:redhat:enterprise_linux:8::baseos"
              ],
              "defaultStatus": "affected",
              "packageName": "openssh",
              "product": "Red Hat Enterprise Linux 8",
              "vendor": "Red Hat",
              "versions": [
                {
                  "lessThan": "*",
                  "status": "unaffected",
                  "version": "0:8.0p1-26.el8_10",
                  "versionType": "rpm"
                }
              ]
            },
            {
              "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
              "cpes": [
                "cpe:/a:redhat:enterprise_linux:8::appstream",
                "cpe:/o:redhat:enterprise_linux:8::baseos"
              ],
              "defaultStatus": "affected",
              "packageName": "openssh",
              "product": "Red Hat Enterprise Linux 8",
              "vendor": "Red Hat",
              "versions": [
                {
                  "lessThan": "*",
                  "status": "unaffected",
                  "version": "0:8.0p1-26.el8_10",
                  "versionType": "rpm"
                }
              ]
            },
            {
              "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
              "cpes": [
                "cpe:/a:redhat:enterprise_linux:9::appstream",
                "cpe:/o:redhat:enterprise_linux:9::baseos"
              ],
              "defaultStatus": "affected",
              "packageName": "openssh",
              "product": "Red Hat Enterprise Linux 9",
              "vendor": "Red Hat",
              "versions": [
                {
                  "lessThan": "*",
                  "status": "unaffected",
                  "version": "0:8.7p1-45.el9",
                  "versionType": "rpm"
                }
              ]
            },
            {
              "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
              "cpes": [
                "cpe:/a:redhat:enterprise_linux:9::appstream",
                "cpe:/o:redhat:enterprise_linux:9::baseos"
              ],
              "defaultStatus": "affected",
              "packageName": "openssh",
              "product": "Red Hat Enterprise Linux 9",
              "vendor": "Red Hat",
              "versions": [
                {
                  "lessThan": "*",
                  "status": "unaffected",
                  "version": "0:8.7p1-45.el9",
                  "versionType": "rpm"
                }
              ]
            },
            {
              "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
              "cpes": [
                "cpe:/a:redhat:rhel_eus:9.4::appstream",
                "cpe:/o:redhat:rhel_eus:9.4::baseos"
              ],
              "defaultStatus": "affected",
              "packageName": "openssh",
              "product": "Red Hat Enterprise Linux 9.4 Extended Update Support",
              "vendor": "Red Hat",
              "versions": [
                {
                  "lessThan": "*",
                  "status": "unaffected",
                  "version": "0:8.7p1-38.el9_4.5",
                  "versionType": "rpm"
                }
              ]
            },
            {
              "collectionURL": "https://catalog.redhat.com/software/containers/",
              "cpes": [
                "cpe:/a:redhat:discovery:1.14::el9"
              ],
              "defaultStatus": "affected",
              "packageName": "discovery/discovery-server-rhel9",
              "product": "Red Hat Discovery 1.14",
              "vendor": "Red Hat",
              "versions": [
                {
                  "lessThan": "*",
                  "status": "unaffected",
                  "version": "1.14.3-1748529279",
                  "versionType": "rpm"
                }
              ]
            },
            {
              "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
              "cpes": [
                "cpe:/o:redhat:enterprise_linux:10"
              ],
              "defaultStatus": "unaffected",
              "packageName": "openssh",
              "product": "Red Hat Enterprise Linux 10",
              "vendor": "Red Hat"
            },
            {
              "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
              "cpes": [
                "cpe:/o:redhat:enterprise_linux:6"
              ],
              "defaultStatus": "unknown",
              "packageName": "openssh",
              "product": "Red Hat Enterprise Linux 6",
              "vendor": "Red Hat"
            },
            {
              "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
              "cpes": [
                "cpe:/o:redhat:enterprise_linux:7"
              ],
              "defaultStatus": "unknown",
              "packageName": "openssh",
              "product": "Red Hat Enterprise Linux 7",
              "vendor": "Red Hat"
            },
            {
              "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
              "cpes": [
                "cpe:/a:redhat:openshift:4"
              ],
              "defaultStatus": "affected",
              "packageName": "rhcos",
              "product": "Red Hat OpenShift Container Platform 4",
              "vendor": "Red Hat"
            }
          ],
          "datePublic": "2025-02-17T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "A vulnerability was found in OpenSSH when the VerifyHostKeyDNS option is enabled. A machine-in-the-middle attack can be performed by a malicious machine impersonating a legit server. This issue occurs due to how OpenSSH mishandles error codes in specific conditions when verifying the host key. For an attack to be considered successful, the attacker needs to manage to exhaust the client\u0027s memory resource first, turning the attack complexity high."
            }
          ],
          "metrics": [
            {
              "other": {
                "content": {
                  "namespace": "https://access.redhat.com/security/updates/classification/",
                  "value": "Moderate"
                },
                "type": "Red Hat severity rating"
              }
            },
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 6.8,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-390",
                  "description": "Detection of Error Condition Without Action",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-02T01:41:44.931Z",
            "orgId": "53f830b8-0a3f-465b-8143-3b8a9948e749",
            "shortName": "redhat"
          },
          "references": [
            {
              "name": "RHSA-2025:16823",
              "tags": [
                "vendor-advisory",
                "x_refsource_REDHAT"
              ],
              "url": "https://access.redhat.com/errata/RHSA-2025:16823"
            },
            {
              "name": "RHSA-2025:3837",
              "tags": [
                "vendor-advisory",
                "x_refsource_REDHAT"
              ],
              "url": "https://access.redhat.com/errata/RHSA-2025:3837"
            },
            {
              "name": "RHSA-2025:6993",
              "tags": [
                "vendor-advisory",
                "x_refsource_REDHAT"
              ],
              "url": "https://access.redhat.com/errata/RHSA-2025:6993"
            },
            {
              "name": "RHSA-2025:8385",
              "tags": [
                "vendor-advisory",
                "x_refsource_REDHAT"
              ],
              "url": "https://access.redhat.com/errata/RHSA-2025:8385"
            },
            {
              "tags": [
                "vdb-entry",
                "x_refsource_REDHAT"
              ],
              "url": "https://access.redhat.com/security/cve/CVE-2025-26465"
            },
            {
              "url": "https://access.redhat.com/solutions/7109879"
            },
            {
              "name": "RHBZ#2344780",
              "tags": [
                "issue-tracking",
                "x_refsource_REDHAT"
              ],
              "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2344780"
            },
            {
              "url": "https://seclists.org/oss-sec/2025/q1/144"
            }
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2025-02-10T21:56:03.853Z",
              "value": "Reported to Red Hat."
            },
            {
              "lang": "en",
              "time": "2025-02-17T00:00:00.000Z",
              "value": "Made public."
            }
          ],
          "title": "Openssh: machine-in-the-middle attack if verifyhostkeydns is enabled",
          "workarounds": [
            {
              "lang": "en",
              "value": "This issue can be mitigated by disabling VerifyHostKeyDNS by setting that option to \u0027no\u0027 in an SSH client configuration file (such as /etc/ssh/ssh_config, ~/.ssh/config, or one of the files in the /etc/ssh/ssh_config.d/ directory). This is the default configuration in Red Hat Enterprise Linux.\n\nFor configurations that require VerifyHostKeyDNS to be enabled (set to either \u0027yes\u0027 or \u0027ask\u0027), mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability."
            }
          ],
          "x_generator": {
            "engine": "cvelib 1.8.0"
          },
          "x_redhatCweChain": "CWE-390: Detection of Error Condition Without Action"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "53f830b8-0a3f-465b-8143-3b8a9948e749",
        "assignerShortName": "redhat",
        "cveId": "CVE-2025-26465",
        "datePublished": "2025-02-18T18:27:16.843Z",
        "dateReserved": "2025-02-10T18:31:47.978Z",
        "dateUpdated": "2026-09-02T01:41:44.931Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2025-0167 (GCVE-0-2025-0167)

    Vulnerability from nvd – Published: 2025-02-05 09:15 – Updated: 2025-03-07 00:10
    VLAI
    Title
    netrc and default credential leak
    Summary
    When asked to use a `.netrc` file for credentials **and** to follow HTTP redirects, curl could leak the password used for the first host to the followed-to host under certain circumstances. This flaw only manifests itself if the netrc file has a `default` entry that omits both login and password. A rare circumstance.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-02-05 15:52 UTC
    Impacted products
    Vendor Product Version
    curl curl Affected: 8.11.1 , ≤ 8.11.1 (semver)
    Affected: 8.11.0 , ≤ 8.11.0 (semver)
    Affected: 8.10.1 , ≤ 8.10.1 (semver)
    Affected: 8.10.0 , ≤ 8.10.0 (semver)
    Affected: 8.9.1 , ≤ 8.9.1 (semver)
    Affected: 8.9.0 , ≤ 8.9.0 (semver)
    Affected: 8.8.0 , ≤ 8.8.0 (semver)
    Affected: 8.7.1 , ≤ 8.7.1 (semver)
    Affected: 8.7.0 , ≤ 8.7.0 (semver)
    Affected: 8.6.0 , ≤ 8.6.0 (semver)
    Affected: 8.5.0 , ≤ 8.5.0 (semver)
    Affected: 8.4.0 , ≤ 8.4.0 (semver)
    Affected: 8.3.0 , ≤ 8.3.0 (semver)
    Affected: 8.2.1 , ≤ 8.2.1 (semver)
    Affected: 8.2.0 , ≤ 8.2.0 (semver)
    Affected: 8.1.2 , ≤ 8.1.2 (semver)
    Affected: 8.1.1 , ≤ 8.1.1 (semver)
    Affected: 8.1.0 , ≤ 8.1.0 (semver)
    Affected: 8.0.1 , ≤ 8.0.1 (semver)
    Affected: 8.0.0 , ≤ 8.0.0 (semver)
    Affected: 7.88.1 , ≤ 7.88.1 (semver)
    Affected: 7.88.0 , ≤ 7.88.0 (semver)
    Affected: 7.87.0 , ≤ 7.87.0 (semver)
    Affected: 7.86.0 , ≤ 7.86.0 (semver)
    Affected: 7.85.0 , ≤ 7.85.0 (semver)
    Affected: 7.84.0 , ≤ 7.84.0 (semver)
    Affected: 7.83.1 , ≤ 7.83.1 (semver)
    Affected: 7.83.0 , ≤ 7.83.0 (semver)
    Affected: 7.82.0 , ≤ 7.82.0 (semver)
    Affected: 7.81.0 , ≤ 7.81.0 (semver)
    Affected: 7.80.0 , ≤ 7.80.0 (semver)
    Affected: 7.79.1 , ≤ 7.79.1 (semver)
    Affected: 7.79.0 , ≤ 7.79.0 (semver)
    Affected: 7.78.0 , ≤ 7.78.0 (semver)
    Affected: 7.77.0 , ≤ 7.77.0 (semver)
    Affected: 7.76.1 , ≤ 7.76.1 (semver)
    Affected: 7.76.0 , ≤ 7.76.0 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "HIGH",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "NONE",
                  "baseScore": 3.4,
                  "baseSeverity": "LOW",
                  "confidentialityImpact": "LOW",
                  "integrityImpact": "NONE",
                  "privilegesRequired": "NONE",
                  "scope": "CHANGED",
                  "userInteraction": "REQUIRED",
                  "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-0167",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-02-05T15:52:41.551530Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-02-06T14:48:00.488Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "exploit"
                ],
                "url": "https://curl.se/docs/CVE-2025-0167.html"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2025-03-07T00:10:48.290Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "url": "https://security.netapp.com/advisory/ntap-20250306-0008/"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "curl",
              "vendor": "curl",
              "versions": [
                {
                  "lessThanOrEqual": "8.11.1",
                  "status": "affected",
                  "version": "8.11.1",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "8.11.0",
                  "status": "affected",
                  "version": "8.11.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "8.10.1",
                  "status": "affected",
                  "version": "8.10.1",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "8.10.0",
                  "status": "affected",
                  "version": "8.10.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "8.9.1",
                  "status": "affected",
                  "version": "8.9.1",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "8.9.0",
                  "status": "affected",
                  "version": "8.9.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "8.8.0",
                  "status": "affected",
                  "version": "8.8.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "8.7.1",
                  "status": "affected",
                  "version": "8.7.1",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "8.7.0",
                  "status": "affected",
                  "version": "8.7.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "8.6.0",
                  "status": "affected",
                  "version": "8.6.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "8.5.0",
                  "status": "affected",
                  "version": "8.5.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "8.4.0",
                  "status": "affected",
                  "version": "8.4.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "8.3.0",
                  "status": "affected",
                  "version": "8.3.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "8.2.1",
                  "status": "affected",
                  "version": "8.2.1",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "8.2.0",
                  "status": "affected",
                  "version": "8.2.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "8.1.2",
                  "status": "affected",
                  "version": "8.1.2",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "8.1.1",
                  "status": "affected",
                  "version": "8.1.1",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "8.1.0",
                  "status": "affected",
                  "version": "8.1.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "8.0.1",
                  "status": "affected",
                  "version": "8.0.1",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "8.0.0",
                  "status": "affected",
                  "version": "8.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.88.1",
                  "status": "affected",
                  "version": "7.88.1",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.88.0",
                  "status": "affected",
                  "version": "7.88.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.87.0",
                  "status": "affected",
                  "version": "7.87.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.86.0",
                  "status": "affected",
                  "version": "7.86.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.85.0",
                  "status": "affected",
                  "version": "7.85.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.84.0",
                  "status": "affected",
                  "version": "7.84.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.83.1",
                  "status": "affected",
                  "version": "7.83.1",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.83.0",
                  "status": "affected",
                  "version": "7.83.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.82.0",
                  "status": "affected",
                  "version": "7.82.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.81.0",
                  "status": "affected",
                  "version": "7.81.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.80.0",
                  "status": "affected",
                  "version": "7.80.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.79.1",
                  "status": "affected",
                  "version": "7.79.1",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.79.0",
                  "status": "affected",
                  "version": "7.79.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.78.0",
                  "status": "affected",
                  "version": "7.78.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.77.0",
                  "status": "affected",
                  "version": "7.77.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.76.1",
                  "status": "affected",
                  "version": "7.76.1",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.76.0",
                  "status": "affected",
                  "version": "7.76.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Yihang Zhou"
            },
            {
              "lang": "en",
              "type": "remediation developer",
              "value": "Daniel Stenberg"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "When asked to use a `.netrc` file for credentials **and** to follow HTTP\nredirects, curl could leak the password used for the first host to the\nfollowed-to host under certain circumstances.\n\nThis flaw only manifests itself if the netrc file has a `default` entry that\nomits both login and password. A rare circumstance."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "CWE-200 Exposure of Sensitive Information to an Unauthorized Actor",
                  "lang": "en"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-02-05T09:15:06.891Z",
            "orgId": "2499f714-1537-4658-8207-48ae4bb9eae9",
            "shortName": "curl"
          },
          "references": [
            {
              "name": "json",
              "url": "https://curl.se/docs/CVE-2025-0167.json"
            },
            {
              "name": "www",
              "url": "https://curl.se/docs/CVE-2025-0167.html"
            },
            {
              "name": "issue",
              "url": "https://hackerone.com/reports/2917232"
            }
          ],
          "title": "netrc and default credential leak"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "2499f714-1537-4658-8207-48ae4bb9eae9",
        "assignerShortName": "curl",
        "cveId": "CVE-2025-0167",
        "datePublished": "2025-02-05T09:15:06.891Z",
        "dateReserved": "2024-12-31T23:07:29.650Z",
        "dateUpdated": "2025-03-07T00:10:48.290Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-11053 (GCVE-0-2024-11053)

    Vulnerability from nvd – Published: 2024-12-11 07:34 – Updated: 2025-11-03 20:36
    VLAI
    Title
    netrc and redirect credential leak
    Summary
    When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, curl could leak the password used for the first host to the followed-to host under certain circumstances. This flaw only manifests itself if the netrc file has an entry that matches the redirect target hostname but the entry either omits just the password or omits both login and password.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-12-15 16:47 UTC
    Impacted products
    Vendor Product Version
    curl curl Affected: 8.11.0 , ≤ 8.11.0 (semver)
    Affected: 8.10.1 , ≤ 8.10.1 (semver)
    Affected: 8.10.0 , ≤ 8.10.0 (semver)
    Affected: 8.9.1 , ≤ 8.9.1 (semver)
    Affected: 8.9.0 , ≤ 8.9.0 (semver)
    Affected: 8.8.0 , ≤ 8.8.0 (semver)
    Affected: 8.7.1 , ≤ 8.7.1 (semver)
    Affected: 8.7.0 , ≤ 8.7.0 (semver)
    Affected: 8.6.0 , ≤ 8.6.0 (semver)
    Affected: 8.5.0 , ≤ 8.5.0 (semver)
    Affected: 8.4.0 , ≤ 8.4.0 (semver)
    Affected: 8.3.0 , ≤ 8.3.0 (semver)
    Affected: 8.2.1 , ≤ 8.2.1 (semver)
    Affected: 8.2.0 , ≤ 8.2.0 (semver)
    Affected: 8.1.2 , ≤ 8.1.2 (semver)
    Affected: 8.1.1 , ≤ 8.1.1 (semver)
    Affected: 8.1.0 , ≤ 8.1.0 (semver)
    Affected: 8.0.1 , ≤ 8.0.1 (semver)
    Affected: 8.0.0 , ≤ 8.0.0 (semver)
    Affected: 7.88.1 , ≤ 7.88.1 (semver)
    Affected: 7.88.0 , ≤ 7.88.0 (semver)
    Affected: 7.87.0 , ≤ 7.87.0 (semver)
    Affected: 7.86.0 , ≤ 7.86.0 (semver)
    Affected: 7.85.0 , ≤ 7.85.0 (semver)
    Affected: 7.84.0 , ≤ 7.84.0 (semver)
    Affected: 7.83.1 , ≤ 7.83.1 (semver)
    Affected: 7.83.0 , ≤ 7.83.0 (semver)
    Affected: 7.82.0 , ≤ 7.82.0 (semver)
    Affected: 7.81.0 , ≤ 7.81.0 (semver)
    Affected: 7.80.0 , ≤ 7.80.0 (semver)
    Affected: 7.79.1 , ≤ 7.79.1 (semver)
    Affected: 7.79.0 , ≤ 7.79.0 (semver)
    Affected: 7.78.0 , ≤ 7.78.0 (semver)
    Affected: 7.77.0 , ≤ 7.77.0 (semver)
    Affected: 7.76.1 , ≤ 7.76.1 (semver)
    Affected: 7.76.0 , ≤ 7.76.0 (semver)
    Affected: 7.75.0 , ≤ 7.75.0 (semver)
    Affected: 7.74.0 , ≤ 7.74.0 (semver)
    Affected: 7.73.0 , ≤ 7.73.0 (semver)
    Affected: 7.72.0 , ≤ 7.72.0 (semver)
    Affected: 7.71.1 , ≤ 7.71.1 (semver)
    Affected: 7.71.0 , ≤ 7.71.0 (semver)
    Affected: 7.70.0 , ≤ 7.70.0 (semver)
    Affected: 7.69.1 , ≤ 7.69.1 (semver)
    Affected: 7.69.0 , ≤ 7.69.0 (semver)
    Affected: 7.68.0 , ≤ 7.68.0 (semver)
    Affected: 7.67.0 , ≤ 7.67.0 (semver)
    Affected: 7.66.0 , ≤ 7.66.0 (semver)
    Affected: 7.65.3 , ≤ 7.65.3 (semver)
    Affected: 7.65.2 , ≤ 7.65.2 (semver)
    Affected: 7.65.1 , ≤ 7.65.1 (semver)
    Affected: 7.65.0 , ≤ 7.65.0 (semver)
    Affected: 7.64.1 , ≤ 7.64.1 (semver)
    Affected: 7.64.0 , ≤ 7.64.0 (semver)
    Affected: 7.63.0 , ≤ 7.63.0 (semver)
    Affected: 7.62.0 , ≤ 7.62.0 (semver)
    Affected: 7.61.1 , ≤ 7.61.1 (semver)
    Affected: 7.61.0 , ≤ 7.61.0 (semver)
    Affected: 7.60.0 , ≤ 7.60.0 (semver)
    Affected: 7.59.0 , ≤ 7.59.0 (semver)
    Affected: 7.58.0 , ≤ 7.58.0 (semver)
    Affected: 7.57.0 , ≤ 7.57.0 (semver)
    Affected: 7.56.1 , ≤ 7.56.1 (semver)
    Affected: 7.56.0 , ≤ 7.56.0 (semver)
    Affected: 7.55.1 , ≤ 7.55.1 (semver)
    Affected: 7.55.0 , ≤ 7.55.0 (semver)
    Affected: 7.54.1 , ≤ 7.54.1 (semver)
    Affected: 7.54.0 , ≤ 7.54.0 (semver)
    Affected: 7.53.1 , ≤ 7.53.1 (semver)
    Affected: 7.53.0 , ≤ 7.53.0 (semver)
    Affected: 7.52.1 , ≤ 7.52.1 (semver)
    Affected: 7.52.0 , ≤ 7.52.0 (semver)
    Affected: 7.51.0 , ≤ 7.51.0 (semver)
    Affected: 7.50.3 , ≤ 7.50.3 (semver)
    Affected: 7.50.2 , ≤ 7.50.2 (semver)
    Affected: 7.50.1 , ≤ 7.50.1 (semver)
    Affected: 7.50.0 , ≤ 7.50.0 (semver)
    Affected: 7.49.1 , ≤ 7.49.1 (semver)
    Affected: 7.49.0 , ≤ 7.49.0 (semver)
    Affected: 7.48.0 , ≤ 7.48.0 (semver)
    Affected: 7.47.1 , ≤ 7.47.1 (semver)
    Affected: 7.47.0 , ≤ 7.47.0 (semver)
    Affected: 7.46.0 , ≤ 7.46.0 (semver)
    Affected: 7.45.0 , ≤ 7.45.0 (semver)
    Affected: 7.44.0 , ≤ 7.44.0 (semver)
    Affected: 7.43.0 , ≤ 7.43.0 (semver)
    Affected: 7.42.1 , ≤ 7.42.1 (semver)
    Affected: 7.42.0 , ≤ 7.42.0 (semver)
    Affected: 7.41.0 , ≤ 7.41.0 (semver)
    Affected: 7.40.0 , ≤ 7.40.0 (semver)
    Affected: 7.39.0 , ≤ 7.39.0 (semver)
    Affected: 7.38.0 , ≤ 7.38.0 (semver)
    Affected: 7.37.1 , ≤ 7.37.1 (semver)
    Affected: 7.37.0 , ≤ 7.37.0 (semver)
    Affected: 7.36.0 , ≤ 7.36.0 (semver)
    Affected: 7.35.0 , ≤ 7.35.0 (semver)
    Affected: 7.34.0 , ≤ 7.34.0 (semver)
    Affected: 7.33.0 , ≤ 7.33.0 (semver)
    Affected: 7.32.0 , ≤ 7.32.0 (semver)
    Affected: 7.31.0 , ≤ 7.31.0 (semver)
    Affected: 7.30.0 , ≤ 7.30.0 (semver)
    Affected: 7.29.0 , ≤ 7.29.0 (semver)
    Affected: 7.28.1 , ≤ 7.28.1 (semver)
    Affected: 7.28.0 , ≤ 7.28.0 (semver)
    Affected: 7.27.0 , ≤ 7.27.0 (semver)
    Affected: 7.26.0 , ≤ 7.26.0 (semver)
    Affected: 7.25.0 , ≤ 7.25.0 (semver)
    Affected: 7.24.0 , ≤ 7.24.0 (semver)
    Affected: 7.23.1 , ≤ 7.23.1 (semver)
    Affected: 7.23.0 , ≤ 7.23.0 (semver)
    Affected: 7.22.0 , ≤ 7.22.0 (semver)
    Affected: 7.21.7 , ≤ 7.21.7 (semver)
    Affected: 7.21.6 , ≤ 7.21.6 (semver)
    Affected: 7.21.5 , ≤ 7.21.5 (semver)
    Affected: 7.21.4 , ≤ 7.21.4 (semver)
    Affected: 7.21.3 , ≤ 7.21.3 (semver)
    Affected: 7.21.2 , ≤ 7.21.2 (semver)
    Affected: 7.21.1 , ≤ 7.21.1 (semver)
    Affected: 7.21.0 , ≤ 7.21.0 (semver)
    Affected: 7.20.1 , ≤ 7.20.1 (semver)
    Affected: 7.20.0 , ≤ 7.20.0 (semver)
    Affected: 7.19.7 , ≤ 7.19.7 (semver)
    Affected: 7.19.6 , ≤ 7.19.6 (semver)
    Affected: 7.19.5 , ≤ 7.19.5 (semver)
    Affected: 7.19.4 , ≤ 7.19.4 (semver)
    Affected: 7.19.3 , ≤ 7.19.3 (semver)
    Affected: 7.19.2 , ≤ 7.19.2 (semver)
    Affected: 7.19.1 , ≤ 7.19.1 (semver)
    Affected: 7.19.0 , ≤ 7.19.0 (semver)
    Affected: 7.18.2 , ≤ 7.18.2 (semver)
    Affected: 7.18.1 , ≤ 7.18.1 (semver)
    Affected: 7.18.0 , ≤ 7.18.0 (semver)
    Affected: 7.17.1 , ≤ 7.17.1 (semver)
    Affected: 7.17.0 , ≤ 7.17.0 (semver)
    Affected: 7.16.4 , ≤ 7.16.4 (semver)
    Affected: 7.16.3 , ≤ 7.16.3 (semver)
    Affected: 7.16.2 , ≤ 7.16.2 (semver)
    Affected: 7.16.1 , ≤ 7.16.1 (semver)
    Affected: 7.16.0 , ≤ 7.16.0 (semver)
    Affected: 7.15.5 , ≤ 7.15.5 (semver)
    Affected: 7.15.4 , ≤ 7.15.4 (semver)
    Affected: 7.15.3 , ≤ 7.15.3 (semver)
    Affected: 7.15.2 , ≤ 7.15.2 (semver)
    Affected: 7.15.1 , ≤ 7.15.1 (semver)
    Affected: 7.15.0 , ≤ 7.15.0 (semver)
    Affected: 7.14.1 , ≤ 7.14.1 (semver)
    Affected: 7.14.0 , ≤ 7.14.0 (semver)
    Affected: 7.13.2 , ≤ 7.13.2 (semver)
    Affected: 7.13.1 , ≤ 7.13.1 (semver)
    Affected: 7.13.0 , ≤ 7.13.0 (semver)
    Affected: 7.12.3 , ≤ 7.12.3 (semver)
    Affected: 7.12.2 , ≤ 7.12.2 (semver)
    Affected: 7.12.1 , ≤ 7.12.1 (semver)
    Affected: 7.12.0 , ≤ 7.12.0 (semver)
    Affected: 7.11.2 , ≤ 7.11.2 (semver)
    Affected: 7.11.1 , ≤ 7.11.1 (semver)
    Affected: 7.11.0 , ≤ 7.11.0 (semver)
    Affected: 7.10.8 , ≤ 7.10.8 (semver)
    Affected: 7.10.7 , ≤ 7.10.7 (semver)
    Affected: 7.10.6 , ≤ 7.10.6 (semver)
    Affected: 7.10.5 , ≤ 7.10.5 (semver)
    Affected: 7.10.4 , ≤ 7.10.4 (semver)
    Affected: 7.10.3 , ≤ 7.10.3 (semver)
    Affected: 7.10.2 , ≤ 7.10.2 (semver)
    Affected: 7.10.1 , ≤ 7.10.1 (semver)
    Affected: 7.10 , ≤ 7.10 (semver)
    Affected: 7.9.8 , ≤ 7.9.8 (semver)
    Affected: 7.9.7 , ≤ 7.9.7 (semver)
    Affected: 7.9.6 , ≤ 7.9.6 (semver)
    Affected: 7.9.5 , ≤ 7.9.5 (semver)
    Affected: 7.9.4 , ≤ 7.9.4 (semver)
    Affected: 7.9.3 , ≤ 7.9.3 (semver)
    Affected: 7.9.2 , ≤ 7.9.2 (semver)
    Affected: 7.9.1 , ≤ 7.9.1 (semver)
    Affected: 7.9 , ≤ 7.9 (semver)
    Affected: 7.8.1 , ≤ 7.8.1 (semver)
    Affected: 7.8 , ≤ 7.8 (semver)
    Affected: 7.7.3 , ≤ 7.7.3 (semver)
    Affected: 7.7.2 , ≤ 7.7.2 (semver)
    Affected: 7.7.1 , ≤ 7.7.1 (semver)
    Affected: 7.7 , ≤ 7.7 (semver)
    Affected: 7.6.1 , ≤ 7.6.1 (semver)
    Affected: 7.6 , ≤ 7.6 (semver)
    Affected: 7.5.2 , ≤ 7.5.2 (semver)
    Affected: 7.5.1 , ≤ 7.5.1 (semver)
    Affected: 7.5 , ≤ 7.5 (semver)
    Affected: 7.4.2 , ≤ 7.4.2 (semver)
    Affected: 7.4.1 , ≤ 7.4.1 (semver)
    Affected: 7.4 , ≤ 7.4 (semver)
    Affected: 7.3 , ≤ 7.3 (semver)
    Affected: 7.2.1 , ≤ 7.2.1 (semver)
    Affected: 7.2 , ≤ 7.2 (semver)
    Affected: 7.1.1 , ≤ 7.1.1 (semver)
    Affected: 7.1 , ≤ 7.1 (semver)
    Affected: 6.5.2 , ≤ 6.5.2 (semver)
    Affected: 6.5.1 , ≤ 6.5.1 (semver)
    Affected: 6.5 , ≤ 6.5 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2025-11-03T20:36:27.027Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "url": "http://www.openwall.com/lists/oss-security/2024/12/11/1"
              },
              {
                "url": "https://security.netapp.com/advisory/ntap-20250124-0012/"
              },
              {
                "url": "https://security.netapp.com/advisory/ntap-20250131-0003/"
              },
              {
                "url": "https://security.netapp.com/advisory/ntap-20250131-0004/"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "HIGH",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "NONE",
                  "baseScore": 3.4,
                  "baseSeverity": "LOW",
                  "confidentialityImpact": "LOW",
                  "integrityImpact": "NONE",
                  "privilegesRequired": "NONE",
                  "scope": "CHANGED",
                  "userInteraction": "REQUIRED",
                  "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-11053",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-12-15T16:47:42.738403Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-12-15T16:50:59.398Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "curl",
              "vendor": "curl",
              "versions": [
                {
                  "lessThanOrEqual": "8.11.0",
                  "status": "affected",
                  "version": "8.11.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "8.10.1",
                  "status": "affected",
                  "version": "8.10.1",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "8.10.0",
                  "status": "affected",
                  "version": "8.10.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "8.9.1",
                  "status": "affected",
                  "version": "8.9.1",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "8.9.0",
                  "status": "affected",
                  "version": "8.9.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "8.8.0",
                  "status": "affected",
                  "version": "8.8.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "8.7.1",
                  "status": "affected",
                  "version": "8.7.1",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "8.7.0",
                  "status": "affected",
                  "version": "8.7.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "8.6.0",
                  "status": "affected",
                  "version": "8.6.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "8.5.0",
                  "status": "affected",
                  "version": "8.5.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "8.4.0",
                  "status": "affected",
                  "version": "8.4.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "8.3.0",
                  "status": "affected",
                  "version": "8.3.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "8.2.1",
                  "status": "affected",
                  "version": "8.2.1",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "8.2.0",
                  "status": "affected",
                  "version": "8.2.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "8.1.2",
                  "status": "affected",
                  "version": "8.1.2",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "8.1.1",
                  "status": "affected",
                  "version": "8.1.1",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "8.1.0",
                  "status": "affected",
                  "version": "8.1.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "8.0.1",
                  "status": "affected",
                  "version": "8.0.1",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "8.0.0",
                  "status": "affected",
                  "version": "8.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.88.1",
                  "status": "affected",
                  "version": "7.88.1",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.88.0",
                  "status": "affected",
                  "version": "7.88.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.87.0",
                  "status": "affected",
                  "version": "7.87.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.86.0",
                  "status": "affected",
                  "version": "7.86.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.85.0",
                  "status": "affected",
                  "version": "7.85.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.84.0",
                  "status": "affected",
                  "version": "7.84.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.83.1",
                  "status": "affected",
                  "version": "7.83.1",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.83.0",
                  "status": "affected",
                  "version": "7.83.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.82.0",
                  "status": "affected",
                  "version": "7.82.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.81.0",
                  "status": "affected",
                  "version": "7.81.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.80.0",
                  "status": "affected",
                  "version": "7.80.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.79.1",
                  "status": "affected",
                  "version": "7.79.1",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.79.0",
                  "status": "affected",
                  "version": "7.79.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.78.0",
                  "status": "affected",
                  "version": "7.78.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.77.0",
                  "status": "affected",
                  "version": "7.77.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.76.1",
                  "status": "affected",
                  "version": "7.76.1",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.76.0",
                  "status": "affected",
                  "version": "7.76.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.75.0",
                  "status": "affected",
                  "version": "7.75.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.74.0",
                  "status": "affected",
                  "version": "7.74.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.73.0",
                  "status": "affected",
                  "version": "7.73.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.72.0",
                  "status": "affected",
                  "version": "7.72.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.71.1",
                  "status": "affected",
                  "version": "7.71.1",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.71.0",
                  "status": "affected",
                  "version": "7.71.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.70.0",
                  "status": "affected",
                  "version": "7.70.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.69.1",
                  "status": "affected",
                  "version": "7.69.1",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.69.0",
                  "status": "affected",
                  "version": "7.69.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.68.0",
                  "status": "affected",
                  "version": "7.68.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.67.0",
                  "status": "affected",
                  "version": "7.67.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.66.0",
                  "status": "affected",
                  "version": "7.66.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.65.3",
                  "status": "affected",
                  "version": "7.65.3",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.65.2",
                  "status": "affected",
                  "version": "7.65.2",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.65.1",
                  "status": "affected",
                  "version": "7.65.1",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.65.0",
                  "status": "affected",
                  "version": "7.65.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.64.1",
                  "status": "affected",
                  "version": "7.64.1",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.64.0",
                  "status": "affected",
                  "version": "7.64.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.63.0",
                  "status": "affected",
                  "version": "7.63.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.62.0",
                  "status": "affected",
                  "version": "7.62.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.61.1",
                  "status": "affected",
                  "version": "7.61.1",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.61.0",
                  "status": "affected",
                  "version": "7.61.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.60.0",
                  "status": "affected",
                  "version": "7.60.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.59.0",
                  "status": "affected",
                  "version": "7.59.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.58.0",
                  "status": "affected",
                  "version": "7.58.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.57.0",
                  "status": "affected",
                  "version": "7.57.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.56.1",
                  "status": "affected",
                  "version": "7.56.1",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.56.0",
                  "status": "affected",
                  "version": "7.56.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.55.1",
                  "status": "affected",
                  "version": "7.55.1",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.55.0",
                  "status": "affected",
                  "version": "7.55.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.54.1",
                  "status": "affected",
                  "version": "7.54.1",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.54.0",
                  "status": "affected",
                  "version": "7.54.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.53.1",
                  "status": "affected",
                  "version": "7.53.1",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.53.0",
                  "status": "affected",
                  "version": "7.53.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.52.1",
                  "status": "affected",
                  "version": "7.52.1",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.52.0",
                  "status": "affected",
                  "version": "7.52.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.51.0",
                  "status": "affected",
                  "version": "7.51.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.50.3",
                  "status": "affected",
                  "version": "7.50.3",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.50.2",
                  "status": "affected",
                  "version": "7.50.2",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.50.1",
                  "status": "affected",
                  "version": "7.50.1",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.50.0",
                  "status": "affected",
                  "version": "7.50.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.49.1",
                  "status": "affected",
                  "version": "7.49.1",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.49.0",
                  "status": "affected",
                  "version": "7.49.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.48.0",
                  "status": "affected",
                  "version": "7.48.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.47.1",
                  "status": "affected",
                  "version": "7.47.1",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.47.0",
                  "status": "affected",
                  "version": "7.47.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.46.0",
                  "status": "affected",
                  "version": "7.46.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.45.0",
                  "status": "affected",
                  "version": "7.45.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.44.0",
                  "status": "affected",
                  "version": "7.44.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.43.0",
                  "status": "affected",
                  "version": "7.43.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.42.1",
                  "status": "affected",
                  "version": "7.42.1",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.42.0",
                  "status": "affected",
                  "version": "7.42.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.41.0",
                  "status": "affected",
                  "version": "7.41.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.40.0",
                  "status": "affected",
                  "version": "7.40.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.39.0",
                  "status": "affected",
                  "version": "7.39.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.38.0",
                  "status": "affected",
                  "version": "7.38.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.37.1",
                  "status": "affected",
                  "version": "7.37.1",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.37.0",
                  "status": "affected",
                  "version": "7.37.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.36.0",
                  "status": "affected",
                  "version": "7.36.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.35.0",
                  "status": "affected",
                  "version": "7.35.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.34.0",
                  "status": "affected",
                  "version": "7.34.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.33.0",
                  "status": "affected",
                  "version": "7.33.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.32.0",
                  "status": "affected",
                  "version": "7.32.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.31.0",
                  "status": "affected",
                  "version": "7.31.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.30.0",
                  "status": "affected",
                  "version": "7.30.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.29.0",
                  "status": "affected",
                  "version": "7.29.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.28.1",
                  "status": "affected",
                  "version": "7.28.1",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.28.0",
                  "status": "affected",
                  "version": "7.28.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.27.0",
                  "status": "affected",
                  "version": "7.27.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.26.0",
                  "status": "affected",
                  "version": "7.26.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.25.0",
                  "status": "affected",
                  "version": "7.25.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.24.0",
                  "status": "affected",
                  "version": "7.24.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.23.1",
                  "status": "affected",
                  "version": "7.23.1",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.23.0",
                  "status": "affected",
                  "version": "7.23.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.22.0",
                  "status": "affected",
                  "version": "7.22.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.21.7",
                  "status": "affected",
                  "version": "7.21.7",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.21.6",
                  "status": "affected",
                  "version": "7.21.6",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.21.5",
                  "status": "affected",
                  "version": "7.21.5",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.21.4",
                  "status": "affected",
                  "version": "7.21.4",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.21.3",
                  "status": "affected",
                  "version": "7.21.3",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.21.2",
                  "status": "affected",
                  "version": "7.21.2",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.21.1",
                  "status": "affected",
                  "version": "7.21.1",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.21.0",
                  "status": "affected",
                  "version": "7.21.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.20.1",
                  "status": "affected",
                  "version": "7.20.1",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.20.0",
                  "status": "affected",
                  "version": "7.20.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.19.7",
                  "status": "affected",
                  "version": "7.19.7",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.19.6",
                  "status": "affected",
                  "version": "7.19.6",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.19.5",
                  "status": "affected",
                  "version": "7.19.5",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.19.4",
                  "status": "affected",
                  "version": "7.19.4",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.19.3",
                  "status": "affected",
                  "version": "7.19.3",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.19.2",
                  "status": "affected",
                  "version": "7.19.2",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.19.1",
                  "status": "affected",
                  "version": "7.19.1",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.19.0",
                  "status": "affected",
                  "version": "7.19.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.18.2",
                  "status": "affected",
                  "version": "7.18.2",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.18.1",
                  "status": "affected",
                  "version": "7.18.1",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.18.0",
                  "status": "affected",
                  "version": "7.18.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.17.1",
                  "status": "affected",
                  "version": "7.17.1",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.17.0",
                  "status": "affected",
                  "version": "7.17.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.16.4",
                  "status": "affected",
                  "version": "7.16.4",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.16.3",
                  "status": "affected",
                  "version": "7.16.3",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.16.2",
                  "status": "affected",
                  "version": "7.16.2",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.16.1",
                  "status": "affected",
                  "version": "7.16.1",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.16.0",
                  "status": "affected",
                  "version": "7.16.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.15.5",
                  "status": "affected",
                  "version": "7.15.5",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.15.4",
                  "status": "affected",
                  "version": "7.15.4",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.15.3",
                  "status": "affected",
                  "version": "7.15.3",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.15.2",
                  "status": "affected",
                  "version": "7.15.2",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.15.1",
                  "status": "affected",
                  "version": "7.15.1",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.15.0",
                  "status": "affected",
                  "version": "7.15.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.14.1",
                  "status": "affected",
                  "version": "7.14.1",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.14.0",
                  "status": "affected",
                  "version": "7.14.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.13.2",
                  "status": "affected",
                  "version": "7.13.2",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.13.1",
                  "status": "affected",
                  "version": "7.13.1",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.13.0",
                  "status": "affected",
                  "version": "7.13.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.12.3",
                  "status": "affected",
                  "version": "7.12.3",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.12.2",
                  "status": "affected",
                  "version": "7.12.2",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.12.1",
                  "status": "affected",
                  "version": "7.12.1",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.12.0",
                  "status": "affected",
                  "version": "7.12.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.11.2",
                  "status": "affected",
                  "version": "7.11.2",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.11.1",
                  "status": "affected",
                  "version": "7.11.1",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.11.0",
                  "status": "affected",
                  "version": "7.11.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.10.8",
                  "status": "affected",
                  "version": "7.10.8",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.10.7",
                  "status": "affected",
                  "version": "7.10.7",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.10.6",
                  "status": "affected",
                  "version": "7.10.6",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.10.5",
                  "status": "affected",
                  "version": "7.10.5",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.10.4",
                  "status": "affected",
                  "version": "7.10.4",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.10.3",
                  "status": "affected",
                  "version": "7.10.3",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.10.2",
                  "status": "affected",
                  "version": "7.10.2",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.10.1",
                  "status": "affected",
                  "version": "7.10.1",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.10",
                  "status": "affected",
                  "version": "7.10",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.9.8",
                  "status": "affected",
                  "version": "7.9.8",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.9.7",
                  "status": "affected",
                  "version": "7.9.7",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.9.6",
                  "status": "affected",
                  "version": "7.9.6",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.9.5",
                  "status": "affected",
                  "version": "7.9.5",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.9.4",
                  "status": "affected",
                  "version": "7.9.4",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.9.3",
                  "status": "affected",
                  "version": "7.9.3",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.9.2",
                  "status": "affected",
                  "version": "7.9.2",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.9.1",
                  "status": "affected",
                  "version": "7.9.1",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.9",
                  "status": "affected",
                  "version": "7.9",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.8.1",
                  "status": "affected",
                  "version": "7.8.1",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.8",
                  "status": "affected",
                  "version": "7.8",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.7.3",
                  "status": "affected",
                  "version": "7.7.3",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.7.2",
                  "status": "affected",
                  "version": "7.7.2",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.7.1",
                  "status": "affected",
                  "version": "7.7.1",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.7",
                  "status": "affected",
                  "version": "7.7",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.6.1",
                  "status": "affected",
                  "version": "7.6.1",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.6",
                  "status": "affected",
                  "version": "7.6",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.5.2",
                  "status": "affected",
                  "version": "7.5.2",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.5.1",
                  "status": "affected",
                  "version": "7.5.1",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.5",
                  "status": "affected",
                  "version": "7.5",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.4.2",
                  "status": "affected",
                  "version": "7.4.2",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.4.1",
                  "status": "affected",
                  "version": "7.4.1",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.4",
                  "status": "affected",
                  "version": "7.4",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.3",
                  "status": "affected",
                  "version": "7.3",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.2.1",
                  "status": "affected",
                  "version": "7.2.1",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.2",
                  "status": "affected",
                  "version": "7.2",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.1.1",
                  "status": "affected",
                  "version": "7.1.1",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.1",
                  "status": "affected",
                  "version": "7.1",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.5.2",
                  "status": "affected",
                  "version": "6.5.2",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.5.1",
                  "status": "affected",
                  "version": "6.5.1",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.5",
                  "status": "affected",
                  "version": "6.5",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Harry Sintonen"
            },
            {
              "lang": "en",
              "type": "remediation developer",
              "value": "Daniel Stenberg"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "When asked to both use a `.netrc` file for credentials and to follow HTTP\nredirects, curl could leak the password used for the first host to the\nfollowed-to host under certain circumstances.\n\nThis flaw only manifests itself if the netrc file has an entry that matches\nthe redirect target hostname but the entry either omits just the password or\nomits both login and password."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "CWE-200 Exposure of Sensitive Information to an Unauthorized Actor",
                  "lang": "en"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-12-11T07:34:29.539Z",
            "orgId": "2499f714-1537-4658-8207-48ae4bb9eae9",
            "shortName": "curl"
          },
          "references": [
            {
              "name": "json",
              "url": "https://curl.se/docs/CVE-2024-11053.json"
            },
            {
              "name": "www",
              "url": "https://curl.se/docs/CVE-2024-11053.html"
            },
            {
              "name": "issue",
              "url": "https://hackerone.com/reports/2829063"
            }
          ],
          "title": "netrc and redirect credential leak"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "2499f714-1537-4658-8207-48ae4bb9eae9",
        "assignerShortName": "curl",
        "cveId": "CVE-2024-11053",
        "datePublished": "2024-12-11T07:34:29.539Z",
        "dateReserved": "2024-11-09T18:41:55.703Z",
        "dateUpdated": "2025-11-03T20:36:27.027Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2024-8932 (GCVE-0-2024-8932)

    Vulnerability from nvd – Published: 2024-11-22 06:03 – Updated: 2025-11-03 22:33
    VLAI
    Title
    OOB access in ldap_escape
    Summary
    In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, uncontrolled long string inputs to ldap_escape() function on 32-bit systems can cause an integer overflow, resulting in an out-of-bounds write.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-11-26 00:00 UTC
    CWE
    Impacted products
    Vendor Product Version
    PHP Group PHP Affected: 8.1.* , < 8.1.31 (semver)
    Affected: 8.2.* , < 8.2.26 (semver)
    Affected: 8.3.* , < 8.3.14 (semver)
    Create a notification for this product.
    php_group php Affected: 8.1.0 , < 8.1.31 (custom)
    Affected: 8.2.0 , < 8.2.26 (custom)
    Affected: 8.3.0 , < 8.3.14 (custom)
        cpe:2.3:a:php_group:php:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2024-11-21 18:15
    Credits
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:php_group:php:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "php",
                "vendor": "php_group",
                "versions": [
                  {
                    "lessThan": "8.1.31",
                    "status": "affected",
                    "version": "8.1.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "8.2.26",
                    "status": "affected",
                    "version": "8.2.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "8.3.14",
                    "status": "affected",
                    "version": "8.3.0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-8932",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-11-26T00:00:00+00:00",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-11-27T04:55:17.998Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2025-11-03T22:33:12.327Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "url": "https://security.netapp.com/advisory/ntap-20250110-0009/"
              },
              {
                "url": "https://lists.debian.org/debian-lts-announce/2024/12/msg00007.html"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "affected",
              "modules": [
                "ldap"
              ],
              "platforms": [
                "32 bit"
              ],
              "product": "PHP",
              "vendor": "PHP Group",
              "versions": [
                {
                  "lessThan": "8.1.31",
                  "status": "affected",
                  "version": "8.1.*",
                  "versionType": "semver"
                },
                {
                  "lessThan": "8.2.26",
                  "status": "affected",
                  "version": "8.2.*",
                  "versionType": "semver"
                },
                {
                  "lessThan": "8.3.14",
                  "status": "affected",
                  "version": "8.3.*",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "Yiheng Cao"
            }
          ],
          "datePublic": "2024-11-21T18:15:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eIn PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, uncontrolled long string inputs to \u003c/span\u003e\u003ccode\u003eldap_escape()\u003c/code\u003e\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003e\u0026nbsp;function on 32-bit systems can cause an integer overflow, resulting in an out-of-bounds write.\u003c/span\u003e\u003cbr\u003e"
                }
              ],
              "value": "In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, uncontrolled long string inputs to ldap_escape()\u00a0function on 32-bit systems can cause an integer overflow, resulting in an out-of-bounds write."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 9.8,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-787",
                  "description": "CWE-787 Out-of-bounds Write",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-11-22T06:03:29.764Z",
            "orgId": "dd77f84a-d19a-4638-8c3d-a322d820ed2b",
            "shortName": "php"
          },
          "references": [
            {
              "url": "https://github.com/php/php-src/security/advisories/GHSA-g665-fm4p-vhff"
            }
          ],
          "source": {
            "advisory": "https://github.com/php/php-src/security/advisories/GHSA-g665-fm4",
            "discovery": "EXTERNAL"
          },
          "title": "OOB access in ldap_escape",
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "dd77f84a-d19a-4638-8c3d-a322d820ed2b",
        "assignerShortName": "php",
        "cveId": "CVE-2024-8932",
        "datePublished": "2024-11-22T06:03:29.764Z",
        "dateReserved": "2024-09-17T04:50:14.830Z",
        "dateUpdated": "2025-11-03T22:33:12.327Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2024-39573 (GCVE-0-2024-39573)

    Vulnerability from nvd – Published: 2024-07-01 18:16 – Updated: 2025-11-03 21:56
    VLAI
    Title
    Apache HTTP Server: mod_rewrite proxy handler substitution
    Summary
    Potential SSRF in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to cause unsafe RewriteRules to unexpectedly setup URL's to be handled by mod_proxy. Users are recommended to upgrade to version 2.4.60, which fixes this issue.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-07-01 20:41 UTC
    CWE
    • CWE-20 - Improper Input Validation
    Impacted products
    Vendor Product Version
    Apache Software Foundation Apache HTTP Server Affected: 2.4.0 , ≤ 2.4.59 (semver)
    Create a notification for this product.
    apache http_server Affected: 2.4.0 , ≤ 2.4.59 (custom)
        cpe:2.3:a:apache:http_server:-:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:apache:http_server:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "http_server",
                "vendor": "apache",
                "versions": [
                  {
                    "lessThanOrEqual": "2.4.59",
                    "status": "affected",
                    "version": "2.4.0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "NONE",
                  "baseScore": 7.5,
                  "baseSeverity": "HIGH",
                  "confidentialityImpact": "HIGH",
                  "integrityImpact": "NONE",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-39573",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-07-01T20:41:48.835121Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-07-01T20:44:44.754Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2025-11-03T21:56:32.361Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "vendor-advisory",
                  "x_transferred"
                ],
                "url": "https://httpd.apache.org/security/vulnerabilities_24.html"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://security.netapp.com/advisory/ntap-20240712-0001/"
              },
              {
                "url": "http://www.openwall.com/lists/oss-security/2024/07/01/11"
              },
              {
                "url": "http://seclists.org/fulldisclosure/2024/Oct/11"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Apache HTTP Server",
              "vendor": "Apache Software Foundation",
              "versions": [
                {
                  "lessThanOrEqual": "2.4.59",
                  "status": "affected",
                  "version": "2.4.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Orange Tsai (@orange_8361) from DEVCORE"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Potential SSRF in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to cause unsafe RewriteRules to unexpectedly setup URL\u0027s to be handled by mod_proxy.\u003cbr\u003eUsers are recommended to upgrade to version 2.4.60, which fixes this issue."
                }
              ],
              "value": "Potential SSRF in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to cause unsafe RewriteRules to unexpectedly setup URL\u0027s to be handled by mod_proxy.\nUsers are recommended to upgrade to version 2.4.60, which fixes this issue."
            }
          ],
          "metrics": [
            {
              "other": {
                "content": {
                  "text": "moderate"
                },
                "type": "Textual description of severity"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-20",
                  "description": "CWE-20 Improper Input Validation",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-07-12T14:06:16.201Z",
            "orgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
            "shortName": "apache"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://httpd.apache.org/security/vulnerabilities_24.html"
            },
            {
              "url": "https://security.netapp.com/advisory/ntap-20240712-0001/"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "timeline": [
            {
              "lang": "en",
              "time": "2024-04-01T12:00:00.000Z",
              "value": "reported"
            }
          ],
          "title": "Apache HTTP Server: mod_rewrite proxy handler substitution",
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
        "assignerShortName": "apache",
        "cveId": "CVE-2024-39573",
        "datePublished": "2024-07-01T18:16:44.297Z",
        "dateReserved": "2024-06-25T17:13:46.679Z",
        "dateUpdated": "2025-11-03T21:56:32.361Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2024-38473 (GCVE-0-2024-38473)

    Vulnerability from nvd – Published: 2024-07-01 18:14 – Updated: 2025-02-13 17:53
    VLAI
    Title
    Apache HTTP Server proxy encoding problem
    Summary
    Encoding problem in mod_proxy in Apache HTTP Server 2.4.59 and earlier allows request URLs with incorrect encoding to be sent to backend services, potentially bypassing authentication via crafted requests. Users are recommended to upgrade to version 2.4.60, which fixes this issue.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-07-24 13:55 UTC
    CWE
    • CWE-116 - Improper Encoding or Escaping of Output
    Impacted products
    Vendor Product Version
    Apache Software Foundation Apache HTTP Server Affected: 2.4.0 , ≤ 2.4.59 (semver)
    Create a notification for this product.
    apache_software_foundation apache_http_server Affected: 2.4.0 , ≤ 2.4.59 (semver)
        cpe:2.3:a:apache_software_foundation:apache_http_server:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:apache_software_foundation:apache_http_server:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "apache_http_server",
                "vendor": "apache_software_foundation",
                "versions": [
                  {
                    "lessThanOrEqual": "2.4.59",
                    "status": "affected",
                    "version": "2.4.0",
                    "versionType": "semver"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "HIGH",
                  "baseScore": 8.1,
                  "baseSeverity": "HIGH",
                  "confidentialityImpact": "HIGH",
                  "integrityImpact": "NONE",
                  "privilegesRequired": "LOW",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-38473",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-07-24T13:55:35.300035Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-07-24T14:02:38.927Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-09-13T17:04:54.566Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "vendor-advisory",
                  "x_transferred"
                ],
                "url": "https://httpd.apache.org/security/vulnerabilities_24.html"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://security.netapp.com/advisory/ntap-20240712-0001/"
              },
              {
                "url": "http://www.openwall.com/lists/oss-security/2024/07/01/6"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Apache HTTP Server",
              "vendor": "Apache Software Foundation",
              "versions": [
                {
                  "lessThanOrEqual": "2.4.59",
                  "status": "affected",
                  "version": "2.4.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Orange Tsai (@orange_8361) from DEVCORE"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Encoding problem in mod_proxy in Apache HTTP Server 2.4.59 and earlier allows request URLs with incorrect encoding to be sent to backend services, potentially bypassing authentication via crafted requests.\u003cbr\u003eUsers are recommended to upgrade to version 2.4.60, which fixes this issue."
                }
              ],
              "value": "Encoding problem in mod_proxy in Apache HTTP Server 2.4.59 and earlier allows request URLs with incorrect encoding to be sent to backend services, potentially bypassing authentication via crafted requests.\nUsers are recommended to upgrade to version 2.4.60, which fixes this issue."
            }
          ],
          "metrics": [
            {
              "other": {
                "content": {
                  "text": "moderate"
                },
                "type": "Textual description of severity"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-116",
                  "description": "CWE-116 Improper Encoding or Escaping of Output",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-07-12T14:06:08.211Z",
            "orgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
            "shortName": "apache"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://httpd.apache.org/security/vulnerabilities_24.html"
            },
            {
              "url": "https://security.netapp.com/advisory/ntap-20240712-0001/"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "timeline": [
            {
              "lang": "en",
              "time": "2024-04-01T12:00:00.000Z",
              "value": "reported"
            }
          ],
          "title": "Apache HTTP Server proxy encoding problem",
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
        "assignerShortName": "apache",
        "cveId": "CVE-2024-38473",
        "datePublished": "2024-07-01T18:14:21.520Z",
        "dateReserved": "2024-06-17T11:05:01.135Z",
        "dateUpdated": "2025-02-13T17:53:12.372Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-38472 (GCVE-0-2024-38472)

    Vulnerability from nvd – Published: 2024-07-01 18:12 – Updated: 2024-11-18 08:51
    VLAI
    Title
    Apache HTTP Server on WIndows UNC SSRF
    Summary
    SSRF in Apache HTTP Server on Windows allows to potentially leak NTLM hashes to a malicious server via SSRF and malicious requests or content Users are recommended to upgrade to version 2.4.60 which fixes this issue.  Note: Existing configurations that access UNC paths will have to configure new directive "UNCList" to allow access during request processing.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-07-25 00:00 UTC
    CWE
    • CWE-918 - Server-Side Request Forgery (SSRF)
    Impacted products
    Vendor Product Version
    Apache Software Foundation Apache HTTP Server Affected: 2.4.0 , ≤ 2.4.59 (semver)
    Create a notification for this product.
    apache_software_foundation apache_http_server Affected: 0 , < 2.4.60 (custom)
        cpe:2.3:a:apache_software_foundation:apache_http_server:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:apache_software_foundation:apache_http_server:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "apache_http_server",
                "vendor": "apache_software_foundation",
                "versions": [
                  {
                    "lessThan": "2.4.60",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "NONE",
                  "baseScore": 7.5,
                  "baseSeverity": "HIGH",
                  "confidentialityImpact": "HIGH",
                  "integrityImpact": "NONE",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-38472",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-07-25T00:00:00+00:00",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-07-26T03:55:30.695Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-09-13T17:04:53.597Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "vendor-advisory",
                  "x_transferred"
                ],
                "url": "https://httpd.apache.org/security/vulnerabilities_24.html"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://security.netapp.com/advisory/ntap-20240712-0001/"
              },
              {
                "url": "http://www.openwall.com/lists/oss-security/2024/07/01/5"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Apache HTTP Server",
              "vendor": "Apache Software Foundation",
              "versions": [
                {
                  "lessThanOrEqual": "2.4.59",
                  "status": "affected",
                  "version": "2.4.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Orange Tsai (@orange_8361) from DEVCORE"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "SSRF in Apache HTTP Server on Windows allows to potentially leak NTLM hashes to a malicious server via SSRF and\u0026nbsp;\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003emalicious requests or content \u003c/span\u003e\u003cbr\u003eUsers are recommended to upgrade to version 2.4.60 which fixes this issue.\u0026nbsp; Note: Existing configurations that access UNC paths will have to configure new directive \"UNCList\" to allow access during request processing."
                }
              ],
              "value": "SSRF in Apache HTTP Server on Windows allows to potentially leak NTLM hashes to a malicious server via SSRF and\u00a0malicious requests or content \nUsers are recommended to upgrade to version 2.4.60 which fixes this issue.\u00a0 Note: Existing configurations that access UNC paths will have to configure new directive \"UNCList\" to allow access during request processing."
            }
          ],
          "metrics": [
            {
              "other": {
                "content": {
                  "text": "important"
                },
                "type": "Textual description of severity"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-918",
                  "description": "CWE-918 Server-Side Request Forgery (SSRF)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-11-18T08:51:23.206Z",
            "orgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
            "shortName": "apache"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://httpd.apache.org/security/vulnerabilities_24.html"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "timeline": [
            {
              "lang": "en",
              "time": "2024-04-01T12:00:00.000Z",
              "value": "reported"
            }
          ],
          "title": "Apache HTTP Server on WIndows UNC SSRF",
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
        "assignerShortName": "apache",
        "cveId": "CVE-2024-38472",
        "datePublished": "2024-07-01T18:12:27.616Z",
        "dateReserved": "2024-06-17T11:02:50.595Z",
        "dateUpdated": "2024-11-18T08:51:23.206Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-36387 (GCVE-0-2024-36387)

    Vulnerability from nvd – Published: 2024-07-01 18:10 – Updated: 2025-02-13 17:52
    VLAI
    Title
    Apache HTTP Server: DoS by Null pointer in websocket over HTTP/2
    Summary
    Serving WebSocket protocol upgrades over a HTTP/2 connection could result in a Null Pointer dereference, leading to a crash of the server process, degrading performance.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-07-22 16:22 UTC
    CWE
    • CWE-476 - NULL Pointer Dereference
    Impacted products
    Vendor Product Version
    Apache Software Foundation Apache HTTP Server Affected: 2.4.55 , ≤ 2.4.59 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "LOW",
                  "baseScore": 5.4,
                  "baseSeverity": "MEDIUM",
                  "confidentialityImpact": "NONE",
                  "integrityImpact": "LOW",
                  "privilegesRequired": "LOW",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-36387",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-07-22T16:22:03.472412Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-11-25T17:28:29.258Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-09-13T17:04:49.998Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "vendor-advisory",
                  "x_transferred"
                ],
                "url": "https://httpd.apache.org/security/vulnerabilities_24.html"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://security.netapp.com/advisory/ntap-20240712-0001/"
              },
              {
                "url": "http://www.openwall.com/lists/oss-security/2024/07/01/4"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Apache HTTP Server",
              "vendor": "Apache Software Foundation",
              "versions": [
                {
                  "lessThanOrEqual": "2.4.59",
                  "status": "affected",
                  "version": "2.4.55",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Marc Stern (\u003cmarc.stern@approach-cyber.com\u003e)"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Serving WebSocket protocol upgrades over a HTTP/2 connection could result in a Null Pointer dereference, leading to a crash of the server process, degrading performance."
                }
              ],
              "value": "Serving WebSocket protocol upgrades over a HTTP/2 connection could result in a Null Pointer dereference, leading to a crash of the server process, degrading performance."
            }
          ],
          "metrics": [
            {
              "other": {
                "content": {
                  "text": "low"
                },
                "type": "Textual description of severity"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-476",
                  "description": "CWE-476 NULL Pointer Dereference",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-07-12T14:06:19.347Z",
            "orgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
            "shortName": "apache"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://httpd.apache.org/security/vulnerabilities_24.html"
            },
            {
              "url": "https://security.netapp.com/advisory/ntap-20240712-0001/"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "timeline": [
            {
              "lang": "en",
              "time": "2024-05-27T13:23:00.000Z",
              "value": "fixed in r1918003 in trunk"
            }
          ],
          "title": "Apache HTTP Server: DoS by Null pointer in websocket over HTTP/2",
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
        "assignerShortName": "apache",
        "cveId": "CVE-2024-36387",
        "datePublished": "2024-07-01T18:10:25.512Z",
        "dateReserved": "2024-05-27T11:13:32.415Z",
        "dateUpdated": "2025-02-13T17:52:53.571Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2026-22049 (GCVE-0-2026-22049)

    Vulnerability from cvelistv5 – Published: 2026-07-22 18:52 – Updated: 2026-07-25 03:55
    VLAI
    Summary
    ONTAP versions 9.16.1 and higher with WebAuthn multi-factor authentication (MFA) configured are susceptible to a vulnerability related to the Relying Party ID which when successfully exploited could allow an attacker with valid credentials to bypass MFA.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-07-24 00:00 UTC
    CWE
    • 288
    • CWE-288 - Authentication Bypass Using an Alternate Path or Channel
    Impacted products
    Vendor Product Version
    NETAPP ONTAP 9 Affected: 9.16.1 , < 9.19.1 (custom)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-22049",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-07-24T00:00:00+00:00",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-288",
                    "description": "CWE-288 Authentication Bypass Using an Alternate Path or Channel",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-07-25T03:55:53.307Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "ONTAP 9",
              "vendor": "NETAPP",
              "versions": [
                {
                  "lessThan": "9.19.1",
                  "status": "affected",
                  "version": "9.16.1",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "ONTAP versions 9.16.1 and higher with WebAuthn multi-factor authentication (MFA) configured are susceptible to a vulnerability related to the Relying Party ID which when successfully exploited could allow an attacker with valid credentials to bypass MFA."
                }
              ],
              "value": "ONTAP versions 9.16.1 and higher with WebAuthn multi-factor authentication (MFA) configured are susceptible to a vulnerability related to the Relying Party ID which when successfully exploited could allow an attacker with valid credentials to bypass MFA."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 8.7,
                "baseSeverity": "HIGH",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "LOW",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "288",
                  "lang": "en"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-07-22T18:52:14.069Z",
            "orgId": "11fdca00-0482-4c88-a206-37f9c182c87d",
            "shortName": "netapp"
          },
          "references": [
            {
              "url": "https://security.netapp.com/advisory/NTAP-20260722-0001/"
            }
          ],
          "source": {
            "advisory": "NTAP-20260722-0001",
            "discovery": "UNKNOWN"
          },
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "11fdca00-0482-4c88-a206-37f9c182c87d",
        "assignerShortName": "netapp",
        "cveId": "CVE-2026-22049",
        "datePublished": "2026-07-22T18:52:14.069Z",
        "dateReserved": "2026-01-05T22:47:18.701Z",
        "dateUpdated": "2026-07-25T03:55:53.307Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-22052 (GCVE-0-2026-22052)

    Vulnerability from cvelistv5 – Published: 2026-03-04 23:22 – Updated: 2026-03-06 18:25
    VLAI
    Summary
    ONTAP versions 9.12.1 and higher with S3 NAS buckets are susceptible to an information disclosure vulnerability. Successful exploit could allow an authenticated attacker to view a listing of the contents in a directory for which they lack permission.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-03-06 18:25 UTC
    CWE
    • 209
    • CWE-209 - Generation of Error Message Containing Sensitive Information
    Impacted products
    Vendor Product Version
    NETAPP ONTAP 9 Affected: 9.12.1 and higher
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-22052",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-03-06T18:25:10.691167Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-209",
                    "description": "CWE-209 Generation of Error Message Containing Sensitive Information",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-03-06T18:25:24.078Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "ONTAP 9",
              "vendor": "NETAPP",
              "versions": [
                {
                  "status": "affected",
                  "version": "9.12.1 and higher"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "ONTAP versions 9.12.1 and higher with S3 NAS buckets are susceptible to an information disclosure vulnerability. Successful exploit could allow an authenticated attacker to view a listing of the contents in a directory for which they lack permission."
                }
              ],
              "value": "ONTAP versions 9.12.1 and higher with S3 NAS buckets are susceptible to an information disclosure vulnerability. Successful exploit could allow an authenticated attacker to view a listing of the contents in a directory for which they lack permission."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "LOW",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "LOW",
                "vulnIntegrityImpact": "NONE",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "209",
                  "lang": "en"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-03-04T23:22:22.957Z",
            "orgId": "11fdca00-0482-4c88-a206-37f9c182c87d",
            "shortName": "netapp"
          },
          "references": [
            {
              "url": "https://security.netapp.com/advisory/NTAP-20260304-0001"
            }
          ],
          "source": {
            "advisory": "NTAP-20260304-0001",
            "discovery": "UNKNOWN"
          },
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "11fdca00-0482-4c88-a206-37f9c182c87d",
        "assignerShortName": "netapp",
        "cveId": "CVE-2026-22052",
        "datePublished": "2026-03-04T23:22:22.957Z",
        "dateReserved": "2026-01-05T22:47:18.701Z",
        "dateUpdated": "2026-03-06T18:25:24.078Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-22050 (GCVE-0-2026-22050)

    Vulnerability from cvelistv5 – Published: 2026-01-12 17:15 – Updated: 2026-01-13 17:30
    VLAI
    Summary
    ONTAP versions 9.16.1 prior to 9.16.1P9 and 9.17.1 prior to 9.17.1P2 with snapshot locking enabled are susceptible to a vulnerability which could allow a privileged remote attacker to set the snapshot expiry time to none.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-01-12 17:36 UTC
    CWE
    • 639
    • CWE-639 - Authorization Bypass Through User-Controlled Key
    Impacted products
    Vendor Product Version
    NETAPP ONTAP 9 Affected: 9.16.1 , < 9.16.1P9 (custom)
    Affected: 9.17.1 , < 9.17.1P2 (custom)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-22050",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-01-12T17:36:52.693542Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-639",
                    "description": "CWE-639 Authorization Bypass Through User-Controlled Key",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-01-13T17:30:51.952Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "ONTAP 9",
              "vendor": "NETAPP",
              "versions": [
                {
                  "lessThan": "9.16.1P9",
                  "status": "affected",
                  "version": "9.16.1",
                  "versionType": "custom"
                },
                {
                  "lessThan": "9.17.1P2",
                  "status": "affected",
                  "version": "9.17.1",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "ONTAP versions 9.16.1 prior to 9.16.1P9 and 9.17.1 prior to 9.17.1P2 with snapshot locking enabled are susceptible to a vulnerability which could allow a privileged remote attacker to set the snapshot expiry time to none."
                }
              ],
              "value": "ONTAP versions 9.16.1 prior to 9.16.1P9 and 9.17.1 prior to 9.17.1P2 with snapshot locking enabled are susceptible to a vulnerability which could allow a privileged remote attacker to set the snapshot expiry time to none."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 6.9,
                "baseSeverity": "MEDIUM",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "HIGH",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "NONE",
                "vulnIntegrityImpact": "HIGH",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "639",
                  "lang": "en"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-01-12T17:15:07.484Z",
            "orgId": "11fdca00-0482-4c88-a206-37f9c182c87d",
            "shortName": "netapp"
          },
          "references": [
            {
              "url": "https://security.netapp.com/advisory/NTAP-20260112-0001"
            }
          ],
          "source": {
            "advisory": "NTAP-20260112-0001",
            "discovery": "EXTERNAL"
          },
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "11fdca00-0482-4c88-a206-37f9c182c87d",
        "assignerShortName": "netapp",
        "cveId": "CVE-2026-22050",
        "datePublished": "2026-01-12T17:15:07.484Z",
        "dateReserved": "2026-01-05T22:47:18.701Z",
        "dateUpdated": "2026-01-13T17:30:51.952Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2025-1861 (GCVE-0-2025-1861)

    Vulnerability from cvelistv5 – Published: 2025-03-30 05:57 – Updated: 2025-11-03 20:57
    VLAI
    Title
    Stream HTTP wrapper truncates redirect location to 1024 bytes
    Summary
    In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when parsing HTTP redirect in the response to an HTTP request, there is currently limit on the location value size caused by limited size of the location buffer to 1024. However as per RFC9110, the limit is recommended to be 8000. This may lead to incorrect URL truncation and redirecting to a wrong location.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-03-31 12:55 UTC
    CWE
    • CWE-131 - Incorrect Calculation of Buffer Size
    Impacted products
    Vendor Product Version
    PHP Group PHP Affected: 8.1.* , < 8.1.32 (semver)
    Affected: 8.2.* , < 8.2.28 (semver)
    Affected: 8.3.* , < 8.3.19 (semver)
    Affected: 8.4.* , < 8.4.5 (semver)
    Create a notification for this product.
    Date Public
    2025-03-23 17:44
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-1861",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-03-31T12:55:53.101020Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-03-31T12:56:00.966Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2025-11-03T20:57:13.769Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "url": "https://security.netapp.com/advisory/ntap-20250523-0005/"
              },
              {
                "url": "https://lists.debian.org/debian-lts-announce/2025/03/msg00014.html"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "affected",
              "product": "PHP",
              "vendor": "PHP Group",
              "versions": [
                {
                  "lessThan": "8.1.32",
                  "status": "affected",
                  "version": "8.1.*",
                  "versionType": "semver"
                },
                {
                  "lessThan": "8.2.28",
                  "status": "affected",
                  "version": "8.2.*",
                  "versionType": "semver"
                },
                {
                  "lessThan": "8.3.19",
                  "status": "affected",
                  "version": "8.3.*",
                  "versionType": "semver"
                },
                {
                  "lessThan": "8.4.5",
                  "status": "affected",
                  "version": "8.4.*",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "Jakub Zelenka"
            }
          ],
          "datePublic": "2025-03-23T17:44:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eIn PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when parsing HTTP redirect in the response to an HTTP request, there is currently limit on the location value size caused by limited size of the location buffer to 1024. However as per RFC9110\u003c/span\u003e\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003e, the limit is recommended to be 8000. This may lead to incorrect URL truncation and redirecting to a wrong location.\u0026nbsp;\u003c/span\u003e\u003cbr\u003e"
                }
              ],
              "value": "In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when parsing HTTP redirect in the response to an HTTP request, there is currently limit on the location value size caused by limited size of the location buffer to 1024. However as per RFC9110, the limit is recommended to be 8000. This may lead to incorrect URL truncation and redirecting to a wrong location."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-220",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-220 Client-Server Protocol Manipulation"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "PRESENT",
                "attackVector": "NETWORK",
                "baseScore": 6.3,
                "baseSeverity": "MEDIUM",
                "privilegesRequired": "NONE",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "LOW",
                "vulnIntegrityImpact": "NONE",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-131",
                  "description": "CWE-131 Incorrect Calculation of Buffer Size",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-03-30T05:57:57.894Z",
            "orgId": "dd77f84a-d19a-4638-8c3d-a322d820ed2b",
            "shortName": "php"
          },
          "references": [
            {
              "url": "https://github.com/php/php-src/security/advisories/GHSA-52jp-hrpf-2jff"
            }
          ],
          "source": {
            "advisory": "https://github.com/php/php-src/security/advisories/GHSA-52jp-hrp",
            "discovery": "INTERNAL"
          },
          "title": "Stream HTTP wrapper truncates redirect location to 1024 bytes",
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "dd77f84a-d19a-4638-8c3d-a322d820ed2b",
        "assignerShortName": "php",
        "cveId": "CVE-2025-1861",
        "datePublished": "2025-03-30T05:57:57.894Z",
        "dateReserved": "2025-03-03T04:47:51.192Z",
        "dateUpdated": "2025-11-03T20:57:13.769Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2025-1736 (GCVE-0-2025-1736)

    Vulnerability from cvelistv5 – Published: 2025-03-30 05:49 – Updated: 2025-11-03 20:57
    VLAI
    Title
    Stream HTTP wrapper header check might omit basic auth header
    Summary
    In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when user-supplied headers are sent, the insufficient validation of the end-of-line characters may prevent certain headers from being sent or lead to certain headers be misinterpreted.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-03-31 12:57 UTC
    CWE
    • CWE-20 - Improper Input Validation
    Impacted products
    Vendor Product Version
    PHP Group PHP Affected: 8.1.* , < 8.1.32 (semver)
    Affected: 8.2.* , < 8.2.28 (semver)
    Affected: 8.3.* , < 8.3.19 (semver)
    Affected: 8.4.* , < 8.4.5 (semver)
    Create a notification for this product.
    Date Public
    2025-03-23 17:43
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-1736",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-03-31T12:57:12.660404Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-03-31T12:57:22.517Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2025-11-03T20:57:10.963Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "url": "https://security.netapp.com/advisory/ntap-20250523-0006/"
              },
              {
                "url": "https://lists.debian.org/debian-lts-announce/2025/03/msg00014.html"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "affected",
              "product": "PHP",
              "vendor": "PHP Group",
              "versions": [
                {
                  "lessThan": "8.1.32",
                  "status": "affected",
                  "version": "8.1.*",
                  "versionType": "semver"
                },
                {
                  "lessThan": "8.2.28",
                  "status": "affected",
                  "version": "8.2.*",
                  "versionType": "semver"
                },
                {
                  "lessThan": "8.3.19",
                  "status": "affected",
                  "version": "8.3.*",
                  "versionType": "semver"
                },
                {
                  "lessThan": "8.4.5",
                  "status": "affected",
                  "version": "8.4.*",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "Jakub Zelenka"
            }
          ],
          "datePublic": "2025-03-23T17:43:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when user-supplied headers are sent, the insufficient validation of the end-of-line characters may prevent certain headers from being sent or lead to certain headers be misinterpreted.\u0026nbsp;"
                }
              ],
              "value": "In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when user-supplied headers are sent, the insufficient validation of the end-of-line characters may prevent certain headers from being sent or lead to certain headers be misinterpreted."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-33",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-33 HTTP Request Smuggling"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "HIGH",
                "attackRequirements": "PRESENT",
                "attackVector": "NETWORK",
                "baseScore": 6.3,
                "baseSeverity": "MEDIUM",
                "privilegesRequired": "NONE",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "LOW",
                "vulnIntegrityImpact": "NONE",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-20",
                  "description": "CWE-20 Improper Input Validation",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-03-30T05:49:14.551Z",
            "orgId": "dd77f84a-d19a-4638-8c3d-a322d820ed2b",
            "shortName": "php"
          },
          "references": [
            {
              "url": "https://github.com/php/php-src/security/advisories/GHSA-hgf5-96fm-v528"
            }
          ],
          "source": {
            "advisory": "https://github.com/php/php-src/security/advisories/GHSA-hgf5-96f",
            "discovery": "INTERNAL"
          },
          "title": "Stream HTTP wrapper header check might omit basic auth header",
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "dd77f84a-d19a-4638-8c3d-a322d820ed2b",
        "assignerShortName": "php",
        "cveId": "CVE-2025-1736",
        "datePublished": "2025-03-30T05:49:14.551Z",
        "dateReserved": "2025-02-27T04:07:07.942Z",
        "dateUpdated": "2025-11-03T20:57:10.963Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2025-1734 (GCVE-0-2025-1734)

    Vulnerability from cvelistv5 – Published: 2025-03-30 05:43 – Updated: 2025-11-03 20:57
    VLAI
    Title
    Streams HTTP wrapper does not fail for headers with invalid name and no colon
    Summary
    In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when receiving headers from HTTP server, the headers missing a colon (:) are treated as valid headers even though they are not. This may confuse applications into accepting invalid headers.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-03-31 14:21 UTC
    CWE
    • CWE-20 - Improper Input Validation
    Impacted products
    Vendor Product Version
    PHP Group PHP Affected: 8.1.* , < 8.1.32 (semver)
    Affected: 8.2.* , < 8.2.28 (semver)
    Affected: 8.3.* , < 8.3.19 (semver)
    Affected: 8.4.* , < 8.4.5 (semver)
    Create a notification for this product.
    Date Public
    2025-03-23 17:43
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-1734",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-03-31T14:21:51.418644Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-04-01T14:37:34.371Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2025-11-03T20:57:09.506Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "url": "https://security.netapp.com/advisory/ntap-20250523-0009/"
              },
              {
                "url": "https://lists.debian.org/debian-lts-announce/2025/03/msg00014.html"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "affected",
              "product": "PHP",
              "vendor": "PHP Group",
              "versions": [
                {
                  "lessThan": "8.1.32",
                  "status": "affected",
                  "version": "8.1.*",
                  "versionType": "semver"
                },
                {
                  "lessThan": "8.2.28",
                  "status": "affected",
                  "version": "8.2.*",
                  "versionType": "semver"
                },
                {
                  "lessThan": "8.3.19",
                  "status": "affected",
                  "version": "8.3.*",
                  "versionType": "semver"
                },
                {
                  "lessThan": "8.4.5",
                  "status": "affected",
                  "version": "8.4.*",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "Jakub Zelenka"
            }
          ],
          "datePublic": "2025-03-23T17:43:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when receiving headers from HTTP server, the headers missing a colon (:) are treated as valid headers even though they are not. This may confuse applications into accepting invalid headers."
                }
              ],
              "value": "In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when receiving headers from HTTP server, the headers missing a colon (:) are treated as valid headers even though they are not. This may confuse applications into accepting invalid headers."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-273",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-273 HTTP Response Smuggling"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "HIGH",
                "attackRequirements": "PRESENT",
                "attackVector": "NETWORK",
                "baseScore": 6.3,
                "baseSeverity": "MEDIUM",
                "privilegesRequired": "NONE",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "LOW",
                "vulnIntegrityImpact": "NONE",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-20",
                  "description": "CWE-20 Improper Input Validation",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-03-30T05:43:35.771Z",
            "orgId": "dd77f84a-d19a-4638-8c3d-a322d820ed2b",
            "shortName": "php"
          },
          "references": [
            {
              "url": "https://github.com/php/php-src/security/advisories/GHSA-pcmh-g36c-qc44"
            }
          ],
          "source": {
            "advisory": "https://github.com/php/php-src/security/advisories/GHSA-pcmh-g36",
            "discovery": "INTERNAL"
          },
          "title": "Streams HTTP wrapper does not fail for headers with invalid name and no colon",
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "dd77f84a-d19a-4638-8c3d-a322d820ed2b",
        "assignerShortName": "php",
        "cveId": "CVE-2025-1734",
        "datePublished": "2025-03-30T05:43:35.771Z",
        "dateReserved": "2025-02-27T04:03:59.544Z",
        "dateUpdated": "2025-11-03T20:57:09.506Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2025-26465 (GCVE-0-2025-26465)

    Vulnerability from cvelistv5 – Published: 2025-02-18 18:27 – Updated: 2026-09-02 01:41
    VLAI
    Title
    Openssh: machine-in-the-middle attack if verifyhostkeydns is enabled
    Summary
    A vulnerability was found in OpenSSH when the VerifyHostKeyDNS option is enabled. A machine-in-the-middle attack can be performed by a malicious machine impersonating a legit server. This issue occurs due to how OpenSSH mishandles error codes in specific conditions when verifying the host key. For an attack to be considered successful, the attacker needs to manage to exhaust the client's memory resource first, turning the attack complexity high.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-02-19 15:02 UTC
    CWE
    • CWE-390 - Detection of Error Condition Without Action
    References
    URL Tags
    https://access.redhat.com/errata/RHSA-2025:16823 vendor-advisoryx_refsource_REDHAT
    https://access.redhat.com/errata/RHSA-2025:3837 vendor-advisoryx_refsource_REDHAT
    https://access.redhat.com/errata/RHSA-2025:6993 vendor-advisoryx_refsource_REDHAT
    https://access.redhat.com/errata/RHSA-2025:8385 vendor-advisoryx_refsource_REDHAT
    https://access.redhat.com/security/cve/CVE-2025-26465 vdb-entryx_refsource_REDHAT
    https://access.redhat.com/solutions/7109879
    https://bugzilla.redhat.com/show_bug.cgi?id=2344780 issue-trackingx_refsource_REDHAT
    https://seclists.org/oss-sec/2025/q1/144
    https://lists.debian.org/debian-lts-announce/2025…
    https://www.openwall.com/lists/oss-security/2025/…
    https://www.openwall.com/lists/oss-security/2025/…
    https://www.theregister.com/2025/02/18/openssh_vu…
    https://bugzilla.suse.com/show_bug.cgi?id=1237040
    https://security-tracker.debian.org/tracker/CVE-2…
    https://ftp.openbsd.org/pub/OpenBSD/patches/7.6/c…
    https://ubuntu.com/security/CVE-2025-26465
    https://www.openssh.com/releasenotes.html#9.9p2
    https://blog.qualys.com/vulnerabilities-threat-re…
    https://lists.mindrot.org/pipermail/openssh-unix-…
    https://security.netapp.com/advisory/ntap-2025022…
    https://www.vicarius.io/vsociety/posts/cve-2025-2…
    https://www.vicarius.io/vsociety/posts/cve-2025-2…
    http://seclists.org/fulldisclosure/2025/May/8
    http://seclists.org/fulldisclosure/2025/May/7
    http://seclists.org/fulldisclosure/2025/Feb/18
    https://cert-portal.siemens.com/productcert/html/…
    https://cert-portal.siemens.com/productcert/html/…
    Impacted products
    Vendor Product Version
    Affected: 6.8p1 , ≤ 9.9p1 (custom)
    Red Hat Red Hat Enterprise Linux 8 Unaffected: 0:8.0p1-26.el8_10 , < * (rpm)
        cpe:/a:redhat:enterprise_linux:8::appstream
        cpe:/o:redhat:enterprise_linux:8::baseos
    Create a notification for this product.
    Red Hat Red Hat Enterprise Linux 9 Unaffected: 0:8.7p1-45.el9 , < * (rpm)
        cpe:/a:redhat:enterprise_linux:9::appstream
        cpe:/o:redhat:enterprise_linux:9::baseos
    Create a notification for this product.
    Red Hat Red Hat Enterprise Linux 9.4 Extended Update Support Unaffected: 0:8.7p1-38.el9_4.5 , < * (rpm)
        cpe:/a:redhat:rhel_eus:9.4::appstream
        cpe:/o:redhat:rhel_eus:9.4::baseos
    Create a notification for this product.
    Red Hat Red Hat Discovery 1.14 Unaffected: 1.14.3-1748529279 , < * (rpm)
        cpe:/a:redhat:discovery:1.14::el9
    Create a notification for this product.
    Red Hat Red Hat Enterprise Linux 10     cpe:/o:redhat:enterprise_linux:10
    Create a notification for this product.
    Red Hat Red Hat Enterprise Linux 6     cpe:/o:redhat:enterprise_linux:6
    Create a notification for this product.
    Red Hat Red Hat Enterprise Linux 7     cpe:/o:redhat:enterprise_linux:7
    Create a notification for this product.
    Red Hat Red Hat OpenShift Container Platform 4     cpe:/a:redhat:openshift:4
    Create a notification for this product.
    Siemens SIDIS Secured SmartPlug Affected: 0 , < V7.26.0310 (custom)
    Create a notification for this product.
    Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP Affected: V3.1.5 , < * (custom)
    Create a notification for this product.
    Siemens SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP Affected: V3.1.5 , < * (custom)
    Create a notification for this product.
    Siemens SIPLUS S7-1500 CPU 1518-4 PN/DP MFP Affected: V3.1.5 , < * (custom)
    Create a notification for this product.
    Date Public
    2025-02-17 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2025-11-03T21:12:55.938Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "url": "https://lists.debian.org/debian-lts-announce/2025/02/msg00020.html"
              },
              {
                "url": "https://www.openwall.com/lists/oss-security/2025/02/18/1"
              },
              {
                "url": "https://www.openwall.com/lists/oss-security/2025/02/18/4"
              },
              {
                "url": "https://www.theregister.com/2025/02/18/openssh_vulnerabilities_mitm_dos/"
              },
              {
                "url": "https://bugzilla.suse.com/show_bug.cgi?id=1237040"
              },
              {
                "url": "https://security-tracker.debian.org/tracker/CVE-2025-26465"
              },
              {
                "url": "https://ftp.openbsd.org/pub/OpenBSD/patches/7.6/common/008_ssh.patch.sig"
              },
              {
                "url": "https://ubuntu.com/security/CVE-2025-26465"
              },
              {
                "url": "https://www.openssh.com/releasenotes.html#9.9p2"
              },
              {
                "url": "https://blog.qualys.com/vulnerabilities-threat-research/2025/02/18/qualys-tru-discovers-two-vulnerabilities-in-openssh-cve-2025-26465-cve-2025-26466"
              },
              {
                "url": "https://lists.mindrot.org/pipermail/openssh-unix-announce/2025-February/000161.html"
              },
              {
                "url": "https://security.netapp.com/advisory/ntap-20250228-0003/"
              },
              {
                "url": "https://www.vicarius.io/vsociety/posts/cve-2025-26465-detect-vulnerable-openssh"
              },
              {
                "url": "https://www.vicarius.io/vsociety/posts/cve-2025-26465-mitigate-vulnerable-openssh"
              },
              {
                "url": "http://seclists.org/fulldisclosure/2025/May/8"
              },
              {
                "url": "http://seclists.org/fulldisclosure/2025/May/7"
              },
              {
                "url": "http://seclists.org/fulldisclosure/2025/Feb/18"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-26465",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-02-19T15:02:09.369445Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-02-19T15:02:45.555Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "exploit"
                ],
                "url": "https://seclists.org/oss-sec/2025/q1/144"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          },
          {
            "affected": [
              {
                "defaultStatus": "unknown",
                "product": "SIDIS Secured SmartPlug",
                "vendor": "Siemens",
                "versions": [
                  {
                    "lessThan": "V7.26.0310",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "defaultStatus": "unknown",
                "product": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP",
                "vendor": "Siemens",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "V3.1.5",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "defaultStatus": "unknown",
                "product": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP",
                "vendor": "Siemens",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "V3.1.5",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "defaultStatus": "unknown",
                "product": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP",
                "vendor": "Siemens",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "V3.1.5",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "defaultStatus": "unknown",
                "product": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP",
                "vendor": "Siemens",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "V3.1.5",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "defaultStatus": "unknown",
                "product": "SIPLUS S7-1500 CPU 1518-4 PN/DP MFP",
                "vendor": "Siemens",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "V3.1.5",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-07-14T12:41:01.736Z",
              "orgId": "0b142b55-0307-4c5a-b3c9-f314f3fb7c5e",
              "shortName": "siemens-SADP"
            },
            "references": [
              {
                "url": "https://cert-portal.siemens.com/productcert/html/ssa-082556.html"
              },
              {
                "url": "https://cert-portal.siemens.com/productcert/html/ssa-585531.html"
              }
            ],
            "x_adpType": "supplier"
          }
        ],
        "cna": {
          "affected": [
            {
              "collectionURL": "https://www.openssh.com/",
              "defaultStatus": "unaffected",
              "packageName": "OpenSSH",
              "repo": "https://anongit.mindrot.org/openssh.git",
              "versions": [
                {
                  "lessThanOrEqual": "9.9p1",
                  "status": "affected",
                  "version": "6.8p1",
                  "versionType": "custom"
                }
              ]
            },
            {
              "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
              "cpes": [
                "cpe:/a:redhat:enterprise_linux:8::appstream",
                "cpe:/o:redhat:enterprise_linux:8::baseos"
              ],
              "defaultStatus": "affected",
              "packageName": "openssh",
              "product": "Red Hat Enterprise Linux 8",
              "vendor": "Red Hat",
              "versions": [
                {
                  "lessThan": "*",
                  "status": "unaffected",
                  "version": "0:8.0p1-26.el8_10",
                  "versionType": "rpm"
                }
              ]
            },
            {
              "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
              "cpes": [
                "cpe:/a:redhat:enterprise_linux:8::appstream",
                "cpe:/o:redhat:enterprise_linux:8::baseos"
              ],
              "defaultStatus": "affected",
              "packageName": "openssh",
              "product": "Red Hat Enterprise Linux 8",
              "vendor": "Red Hat",
              "versions": [
                {
                  "lessThan": "*",
                  "status": "unaffected",
                  "version": "0:8.0p1-26.el8_10",
                  "versionType": "rpm"
                }
              ]
            },
            {
              "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
              "cpes": [
                "cpe:/a:redhat:enterprise_linux:9::appstream",
                "cpe:/o:redhat:enterprise_linux:9::baseos"
              ],
              "defaultStatus": "affected",
              "packageName": "openssh",
              "product": "Red Hat Enterprise Linux 9",
              "vendor": "Red Hat",
              "versions": [
                {
                  "lessThan": "*",
                  "status": "unaffected",
                  "version": "0:8.7p1-45.el9",
                  "versionType": "rpm"
                }
              ]
            },
            {
              "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
              "cpes": [
                "cpe:/a:redhat:enterprise_linux:9::appstream",
                "cpe:/o:redhat:enterprise_linux:9::baseos"
              ],
              "defaultStatus": "affected",
              "packageName": "openssh",
              "product": "Red Hat Enterprise Linux 9",
              "vendor": "Red Hat",
              "versions": [
                {
                  "lessThan": "*",
                  "status": "unaffected",
                  "version": "0:8.7p1-45.el9",
                  "versionType": "rpm"
                }
              ]
            },
            {
              "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
              "cpes": [
                "cpe:/a:redhat:rhel_eus:9.4::appstream",
                "cpe:/o:redhat:rhel_eus:9.4::baseos"
              ],
              "defaultStatus": "affected",
              "packageName": "openssh",
              "product": "Red Hat Enterprise Linux 9.4 Extended Update Support",
              "vendor": "Red Hat",
              "versions": [
                {
                  "lessThan": "*",
                  "status": "unaffected",
                  "version": "0:8.7p1-38.el9_4.5",
                  "versionType": "rpm"
                }
              ]
            },
            {
              "collectionURL": "https://catalog.redhat.com/software/containers/",
              "cpes": [
                "cpe:/a:redhat:discovery:1.14::el9"
              ],
              "defaultStatus": "affected",
              "packageName": "discovery/discovery-server-rhel9",
              "product": "Red Hat Discovery 1.14",
              "vendor": "Red Hat",
              "versions": [
                {
                  "lessThan": "*",
                  "status": "unaffected",
                  "version": "1.14.3-1748529279",
                  "versionType": "rpm"
                }
              ]
            },
            {
              "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
              "cpes": [
                "cpe:/o:redhat:enterprise_linux:10"
              ],
              "defaultStatus": "unaffected",
              "packageName": "openssh",
              "product": "Red Hat Enterprise Linux 10",
              "vendor": "Red Hat"
            },
            {
              "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
              "cpes": [
                "cpe:/o:redhat:enterprise_linux:6"
              ],
              "defaultStatus": "unknown",
              "packageName": "openssh",
              "product": "Red Hat Enterprise Linux 6",
              "vendor": "Red Hat"
            },
            {
              "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
              "cpes": [
                "cpe:/o:redhat:enterprise_linux:7"
              ],
              "defaultStatus": "unknown",
              "packageName": "openssh",
              "product": "Red Hat Enterprise Linux 7",
              "vendor": "Red Hat"
            },
            {
              "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
              "cpes": [
                "cpe:/a:redhat:openshift:4"
              ],
              "defaultStatus": "affected",
              "packageName": "rhcos",
              "product": "Red Hat OpenShift Container Platform 4",
              "vendor": "Red Hat"
            }
          ],
          "datePublic": "2025-02-17T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "A vulnerability was found in OpenSSH when the VerifyHostKeyDNS option is enabled. A machine-in-the-middle attack can be performed by a malicious machine impersonating a legit server. This issue occurs due to how OpenSSH mishandles error codes in specific conditions when verifying the host key. For an attack to be considered successful, the attacker needs to manage to exhaust the client\u0027s memory resource first, turning the attack complexity high."
            }
          ],
          "metrics": [
            {
              "other": {
                "content": {
                  "namespace": "https://access.redhat.com/security/updates/classification/",
                  "value": "Moderate"
                },
                "type": "Red Hat severity rating"
              }
            },
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 6.8,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-390",
                  "description": "Detection of Error Condition Without Action",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-02T01:41:44.931Z",
            "orgId": "53f830b8-0a3f-465b-8143-3b8a9948e749",
            "shortName": "redhat"
          },
          "references": [
            {
              "name": "RHSA-2025:16823",
              "tags": [
                "vendor-advisory",
                "x_refsource_REDHAT"
              ],
              "url": "https://access.redhat.com/errata/RHSA-2025:16823"
            },
            {
              "name": "RHSA-2025:3837",
              "tags": [
                "vendor-advisory",
                "x_refsource_REDHAT"
              ],
              "url": "https://access.redhat.com/errata/RHSA-2025:3837"
            },
            {
              "name": "RHSA-2025:6993",
              "tags": [
                "vendor-advisory",
                "x_refsource_REDHAT"
              ],
              "url": "https://access.redhat.com/errata/RHSA-2025:6993"
            },
            {
              "name": "RHSA-2025:8385",
              "tags": [
                "vendor-advisory",
                "x_refsource_REDHAT"
              ],
              "url": "https://access.redhat.com/errata/RHSA-2025:8385"
            },
            {
              "tags": [
                "vdb-entry",
                "x_refsource_REDHAT"
              ],
              "url": "https://access.redhat.com/security/cve/CVE-2025-26465"
            },
            {
              "url": "https://access.redhat.com/solutions/7109879"
            },
            {
              "name": "RHBZ#2344780",
              "tags": [
                "issue-tracking",
                "x_refsource_REDHAT"
              ],
              "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2344780"
            },
            {
              "url": "https://seclists.org/oss-sec/2025/q1/144"
            }
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2025-02-10T21:56:03.853Z",
              "value": "Reported to Red Hat."
            },
            {
              "lang": "en",
              "time": "2025-02-17T00:00:00.000Z",
              "value": "Made public."
            }
          ],
          "title": "Openssh: machine-in-the-middle attack if verifyhostkeydns is enabled",
          "workarounds": [
            {
              "lang": "en",
              "value": "This issue can be mitigated by disabling VerifyHostKeyDNS by setting that option to \u0027no\u0027 in an SSH client configuration file (such as /etc/ssh/ssh_config, ~/.ssh/config, or one of the files in the /etc/ssh/ssh_config.d/ directory). This is the default configuration in Red Hat Enterprise Linux.\n\nFor configurations that require VerifyHostKeyDNS to be enabled (set to either \u0027yes\u0027 or \u0027ask\u0027), mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability."
            }
          ],
          "x_generator": {
            "engine": "cvelib 1.8.0"
          },
          "x_redhatCweChain": "CWE-390: Detection of Error Condition Without Action"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "53f830b8-0a3f-465b-8143-3b8a9948e749",
        "assignerShortName": "redhat",
        "cveId": "CVE-2025-26465",
        "datePublished": "2025-02-18T18:27:16.843Z",
        "dateReserved": "2025-02-10T18:31:47.978Z",
        "dateUpdated": "2026-09-02T01:41:44.931Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2024-56171 (GCVE-0-2024-56171)

    Vulnerability from cvelistv5 – Published: 2025-02-18 00:00 – Updated: 2025-11-03 20:49
    VLAI
    Summary
    libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a use-after-free in xmlSchemaIDCFillNodeTables and xmlSchemaBubbleIDCNodeTables in xmlschemas.c. To exploit this, a crafted XML document must be validated against an XML schema with certain identity constraints, or a crafted XML schema must be used.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-02-19 16:26 UTC
    CWE
    Impacted products
    Vendor Product Version
    xmlsoft libxml2 Affected: 0 , < 2.12.10 (semver)
    Affected: 2.13.0 , < 2.13.6 (semver)
        cpe:2.3:a:xmlsoft:libxml2:*:*:*:*:*:*:*:*
        cpe:2.3:a:xmlsoft:libxml2:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-56171",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-02-19T16:26:31.484719Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-02-19T16:26:41.297Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2025-11-03T20:49:05.224Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "url": "https://security.netapp.com/advisory/ntap-20250328-0010/"
              },
              {
                "url": "http://seclists.org/fulldisclosure/2025/Apr/13"
              },
              {
                "url": "http://seclists.org/fulldisclosure/2025/Apr/10"
              },
              {
                "url": "http://seclists.org/fulldisclosure/2025/Apr/9"
              },
              {
                "url": "http://seclists.org/fulldisclosure/2025/Apr/8"
              },
              {
                "url": "http://seclists.org/fulldisclosure/2025/Apr/5"
              },
              {
                "url": "http://seclists.org/fulldisclosure/2025/Apr/4"
              },
              {
                "url": "http://seclists.org/fulldisclosure/2025/Apr/12"
              },
              {
                "url": "http://seclists.org/fulldisclosure/2025/Apr/11"
              },
              {
                "url": "https://lists.debian.org/debian-lts-announce/2025/02/msg00028.html"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "libxml2",
              "vendor": "xmlsoft",
              "versions": [
                {
                  "lessThan": "2.12.10",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "2.13.6",
                  "status": "affected",
                  "version": "2.13.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:xmlsoft:libxml2:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "2.12.10",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:xmlsoft:libxml2:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "2.13.6",
                      "versionStartIncluding": "2.13.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a use-after-free in xmlSchemaIDCFillNodeTables and xmlSchemaBubbleIDCNodeTables in xmlschemas.c. To exploit this, a crafted XML document must be validated against an XML schema with certain identity constraints, or a crafted XML schema must be used."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 7.8,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-416",
                  "description": "CWE-416 Use After Free",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-02-18T22:10:20.934Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "url": "https://gitlab.gnome.org/GNOME/libxml2/-/issues/828"
            }
          ],
          "x_generator": {
            "engine": "enrichogram 0.0.1"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2024-56171",
        "datePublished": "2025-02-18T00:00:00.000Z",
        "dateReserved": "2024-12-18T00:00:00.000Z",
        "dateUpdated": "2025-11-03T20:49:05.224Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2025-24928 (GCVE-0-2025-24928)

    Vulnerability from cvelistv5 – Published: 2025-02-18 00:00 – Updated: 2026-02-26 19:08
    VLAI
    Summary
    libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a stack-based buffer overflow in xmlSnprintfElements in valid.c. To exploit this, DTD validation must occur for an untrusted document or untrusted DTD. NOTE: this is similar to CVE-2017-9047.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-07-23 03:55 UTC
    CWE
    • CWE-121 - Stack-based Buffer Overflow
    Impacted products
    Vendor Product Version
    xmlsoft libxml2 Affected: 0 , < 2.12.10 (semver)
    Affected: 2.13.0 , < 2.13.6 (semver)
        cpe:2.3:a:xmlsoft:libxml2:*:*:*:*:*:*:*:*
        cpe:2.3:a:xmlsoft:libxml2:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-24928",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-07-23T03:55:31.854089Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-02-26T19:08:48.412Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2025-11-03T21:12:47.571Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "url": "https://security.netapp.com/advisory/ntap-20250321-0006/"
              },
              {
                "url": "https://lists.debian.org/debian-lts-announce/2025/02/msg00028.html"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "libxml2",
              "vendor": "xmlsoft",
              "versions": [
                {
                  "lessThan": "2.12.10",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "2.13.6",
                  "status": "affected",
                  "version": "2.13.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:xmlsoft:libxml2:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "2.12.10",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:xmlsoft:libxml2:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "2.13.6",
                      "versionStartIncluding": "2.13.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a stack-based buffer overflow in xmlSnprintfElements in valid.c. To exploit this, DTD validation must occur for an untrusted document or untrusted DTD. NOTE: this is similar to CVE-2017-9047."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 7.8,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-121",
                  "description": "CWE-121 Stack-based Buffer Overflow",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-02-18T22:20:43.285Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "url": "https://gitlab.gnome.org/GNOME/libxml2/-/issues/847"
            },
            {
              "url": "https://issues.oss-fuzz.com/issues/392687022"
            }
          ],
          "x_generator": {
            "engine": "enrichogram 0.0.1"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2025-24928",
        "datePublished": "2025-02-18T00:00:00.000Z",
        "dateReserved": "2025-01-28T00:00:00.000Z",
        "dateUpdated": "2026-02-26T19:08:48.412Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2025-0167 (GCVE-0-2025-0167)

    Vulnerability from cvelistv5 – Published: 2025-02-05 09:15 – Updated: 2025-03-07 00:10
    VLAI
    Title
    netrc and default credential leak
    Summary
    When asked to use a `.netrc` file for credentials **and** to follow HTTP redirects, curl could leak the password used for the first host to the followed-to host under certain circumstances. This flaw only manifests itself if the netrc file has a `default` entry that omits both login and password. A rare circumstance.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-02-05 15:52 UTC
    Impacted products
    Vendor Product Version
    curl curl Affected: 8.11.1 , ≤ 8.11.1 (semver)
    Affected: 8.11.0 , ≤ 8.11.0 (semver)
    Affected: 8.10.1 , ≤ 8.10.1 (semver)
    Affected: 8.10.0 , ≤ 8.10.0 (semver)
    Affected: 8.9.1 , ≤ 8.9.1 (semver)
    Affected: 8.9.0 , ≤ 8.9.0 (semver)
    Affected: 8.8.0 , ≤ 8.8.0 (semver)
    Affected: 8.7.1 , ≤ 8.7.1 (semver)
    Affected: 8.7.0 , ≤ 8.7.0 (semver)
    Affected: 8.6.0 , ≤ 8.6.0 (semver)
    Affected: 8.5.0 , ≤ 8.5.0 (semver)
    Affected: 8.4.0 , ≤ 8.4.0 (semver)
    Affected: 8.3.0 , ≤ 8.3.0 (semver)
    Affected: 8.2.1 , ≤ 8.2.1 (semver)
    Affected: 8.2.0 , ≤ 8.2.0 (semver)
    Affected: 8.1.2 , ≤ 8.1.2 (semver)
    Affected: 8.1.1 , ≤ 8.1.1 (semver)
    Affected: 8.1.0 , ≤ 8.1.0 (semver)
    Affected: 8.0.1 , ≤ 8.0.1 (semver)
    Affected: 8.0.0 , ≤ 8.0.0 (semver)
    Affected: 7.88.1 , ≤ 7.88.1 (semver)
    Affected: 7.88.0 , ≤ 7.88.0 (semver)
    Affected: 7.87.0 , ≤ 7.87.0 (semver)
    Affected: 7.86.0 , ≤ 7.86.0 (semver)
    Affected: 7.85.0 , ≤ 7.85.0 (semver)
    Affected: 7.84.0 , ≤ 7.84.0 (semver)
    Affected: 7.83.1 , ≤ 7.83.1 (semver)
    Affected: 7.83.0 , ≤ 7.83.0 (semver)
    Affected: 7.82.0 , ≤ 7.82.0 (semver)
    Affected: 7.81.0 , ≤ 7.81.0 (semver)
    Affected: 7.80.0 , ≤ 7.80.0 (semver)
    Affected: 7.79.1 , ≤ 7.79.1 (semver)
    Affected: 7.79.0 , ≤ 7.79.0 (semver)
    Affected: 7.78.0 , ≤ 7.78.0 (semver)
    Affected: 7.77.0 , ≤ 7.77.0 (semver)
    Affected: 7.76.1 , ≤ 7.76.1 (semver)
    Affected: 7.76.0 , ≤ 7.76.0 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "HIGH",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "NONE",
                  "baseScore": 3.4,
                  "baseSeverity": "LOW",
                  "confidentialityImpact": "LOW",
                  "integrityImpact": "NONE",
                  "privilegesRequired": "NONE",
                  "scope": "CHANGED",
                  "userInteraction": "REQUIRED",
                  "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-0167",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-02-05T15:52:41.551530Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-02-06T14:48:00.488Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "exploit"
                ],
                "url": "https://curl.se/docs/CVE-2025-0167.html"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2025-03-07T00:10:48.290Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "url": "https://security.netapp.com/advisory/ntap-20250306-0008/"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "curl",
              "vendor": "curl",
              "versions": [
                {
                  "lessThanOrEqual": "8.11.1",
                  "status": "affected",
                  "version": "8.11.1",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "8.11.0",
                  "status": "affected",
                  "version": "8.11.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "8.10.1",
                  "status": "affected",
                  "version": "8.10.1",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "8.10.0",
                  "status": "affected",
                  "version": "8.10.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "8.9.1",
                  "status": "affected",
                  "version": "8.9.1",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "8.9.0",
                  "status": "affected",
                  "version": "8.9.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "8.8.0",
                  "status": "affected",
                  "version": "8.8.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "8.7.1",
                  "status": "affected",
                  "version": "8.7.1",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "8.7.0",
                  "status": "affected",
                  "version": "8.7.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "8.6.0",
                  "status": "affected",
                  "version": "8.6.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "8.5.0",
                  "status": "affected",
                  "version": "8.5.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "8.4.0",
                  "status": "affected",
                  "version": "8.4.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "8.3.0",
                  "status": "affected",
                  "version": "8.3.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "8.2.1",
                  "status": "affected",
                  "version": "8.2.1",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "8.2.0",
                  "status": "affected",
                  "version": "8.2.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "8.1.2",
                  "status": "affected",
                  "version": "8.1.2",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "8.1.1",
                  "status": "affected",
                  "version": "8.1.1",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "8.1.0",
                  "status": "affected",
                  "version": "8.1.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "8.0.1",
                  "status": "affected",
                  "version": "8.0.1",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "8.0.0",
                  "status": "affected",
                  "version": "8.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.88.1",
                  "status": "affected",
                  "version": "7.88.1",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.88.0",
                  "status": "affected",
                  "version": "7.88.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.87.0",
                  "status": "affected",
                  "version": "7.87.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.86.0",
                  "status": "affected",
                  "version": "7.86.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.85.0",
                  "status": "affected",
                  "version": "7.85.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.84.0",
                  "status": "affected",
                  "version": "7.84.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.83.1",
                  "status": "affected",
                  "version": "7.83.1",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.83.0",
                  "status": "affected",
                  "version": "7.83.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.82.0",
                  "status": "affected",
                  "version": "7.82.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.81.0",
                  "status": "affected",
                  "version": "7.81.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.80.0",
                  "status": "affected",
                  "version": "7.80.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.79.1",
                  "status": "affected",
                  "version": "7.79.1",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.79.0",
                  "status": "affected",
                  "version": "7.79.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.78.0",
                  "status": "affected",
                  "version": "7.78.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.77.0",
                  "status": "affected",
                  "version": "7.77.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.76.1",
                  "status": "affected",
                  "version": "7.76.1",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.76.0",
                  "status": "affected",
                  "version": "7.76.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Yihang Zhou"
            },
            {
              "lang": "en",
              "type": "remediation developer",
              "value": "Daniel Stenberg"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "When asked to use a `.netrc` file for credentials **and** to follow HTTP\nredirects, curl could leak the password used for the first host to the\nfollowed-to host under certain circumstances.\n\nThis flaw only manifests itself if the netrc file has a `default` entry that\nomits both login and password. A rare circumstance."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "CWE-200 Exposure of Sensitive Information to an Unauthorized Actor",
                  "lang": "en"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-02-05T09:15:06.891Z",
            "orgId": "2499f714-1537-4658-8207-48ae4bb9eae9",
            "shortName": "curl"
          },
          "references": [
            {
              "name": "json",
              "url": "https://curl.se/docs/CVE-2025-0167.json"
            },
            {
              "name": "www",
              "url": "https://curl.se/docs/CVE-2025-0167.html"
            },
            {
              "name": "issue",
              "url": "https://hackerone.com/reports/2917232"
            }
          ],
          "title": "netrc and default credential leak"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "2499f714-1537-4658-8207-48ae4bb9eae9",
        "assignerShortName": "curl",
        "cveId": "CVE-2025-0167",
        "datePublished": "2025-02-05T09:15:06.891Z",
        "dateReserved": "2024-12-31T23:07:29.650Z",
        "dateUpdated": "2025-03-07T00:10:48.290Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-11053 (GCVE-0-2024-11053)

    Vulnerability from cvelistv5 – Published: 2024-12-11 07:34 – Updated: 2025-11-03 20:36
    VLAI
    Title
    netrc and redirect credential leak
    Summary
    When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, curl could leak the password used for the first host to the followed-to host under certain circumstances. This flaw only manifests itself if the netrc file has an entry that matches the redirect target hostname but the entry either omits just the password or omits both login and password.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-12-15 16:47 UTC
    Impacted products
    Vendor Product Version
    curl curl Affected: 8.11.0 , ≤ 8.11.0 (semver)
    Affected: 8.10.1 , ≤ 8.10.1 (semver)
    Affected: 8.10.0 , ≤ 8.10.0 (semver)
    Affected: 8.9.1 , ≤ 8.9.1 (semver)
    Affected: 8.9.0 , ≤ 8.9.0 (semver)
    Affected: 8.8.0 , ≤ 8.8.0 (semver)
    Affected: 8.7.1 , ≤ 8.7.1 (semver)
    Affected: 8.7.0 , ≤ 8.7.0 (semver)
    Affected: 8.6.0 , ≤ 8.6.0 (semver)
    Affected: 8.5.0 , ≤ 8.5.0 (semver)
    Affected: 8.4.0 , ≤ 8.4.0 (semver)
    Affected: 8.3.0 , ≤ 8.3.0 (semver)
    Affected: 8.2.1 , ≤ 8.2.1 (semver)
    Affected: 8.2.0 , ≤ 8.2.0 (semver)
    Affected: 8.1.2 , ≤ 8.1.2 (semver)
    Affected: 8.1.1 , ≤ 8.1.1 (semver)
    Affected: 8.1.0 , ≤ 8.1.0 (semver)
    Affected: 8.0.1 , ≤ 8.0.1 (semver)
    Affected: 8.0.0 , ≤ 8.0.0 (semver)
    Affected: 7.88.1 , ≤ 7.88.1 (semver)
    Affected: 7.88.0 , ≤ 7.88.0 (semver)
    Affected: 7.87.0 , ≤ 7.87.0 (semver)
    Affected: 7.86.0 , ≤ 7.86.0 (semver)
    Affected: 7.85.0 , ≤ 7.85.0 (semver)
    Affected: 7.84.0 , ≤ 7.84.0 (semver)
    Affected: 7.83.1 , ≤ 7.83.1 (semver)
    Affected: 7.83.0 , ≤ 7.83.0 (semver)
    Affected: 7.82.0 , ≤ 7.82.0 (semver)
    Affected: 7.81.0 , ≤ 7.81.0 (semver)
    Affected: 7.80.0 , ≤ 7.80.0 (semver)
    Affected: 7.79.1 , ≤ 7.79.1 (semver)
    Affected: 7.79.0 , ≤ 7.79.0 (semver)
    Affected: 7.78.0 , ≤ 7.78.0 (semver)
    Affected: 7.77.0 , ≤ 7.77.0 (semver)
    Affected: 7.76.1 , ≤ 7.76.1 (semver)
    Affected: 7.76.0 , ≤ 7.76.0 (semver)
    Affected: 7.75.0 , ≤ 7.75.0 (semver)
    Affected: 7.74.0 , ≤ 7.74.0 (semver)
    Affected: 7.73.0 , ≤ 7.73.0 (semver)
    Affected: 7.72.0 , ≤ 7.72.0 (semver)
    Affected: 7.71.1 , ≤ 7.71.1 (semver)
    Affected: 7.71.0 , ≤ 7.71.0 (semver)
    Affected: 7.70.0 , ≤ 7.70.0 (semver)
    Affected: 7.69.1 , ≤ 7.69.1 (semver)
    Affected: 7.69.0 , ≤ 7.69.0 (semver)
    Affected: 7.68.0 , ≤ 7.68.0 (semver)
    Affected: 7.67.0 , ≤ 7.67.0 (semver)
    Affected: 7.66.0 , ≤ 7.66.0 (semver)
    Affected: 7.65.3 , ≤ 7.65.3 (semver)
    Affected: 7.65.2 , ≤ 7.65.2 (semver)
    Affected: 7.65.1 , ≤ 7.65.1 (semver)
    Affected: 7.65.0 , ≤ 7.65.0 (semver)
    Affected: 7.64.1 , ≤ 7.64.1 (semver)
    Affected: 7.64.0 , ≤ 7.64.0 (semver)
    Affected: 7.63.0 , ≤ 7.63.0 (semver)
    Affected: 7.62.0 , ≤ 7.62.0 (semver)
    Affected: 7.61.1 , ≤ 7.61.1 (semver)
    Affected: 7.61.0 , ≤ 7.61.0 (semver)
    Affected: 7.60.0 , ≤ 7.60.0 (semver)
    Affected: 7.59.0 , ≤ 7.59.0 (semver)
    Affected: 7.58.0 , ≤ 7.58.0 (semver)
    Affected: 7.57.0 , ≤ 7.57.0 (semver)
    Affected: 7.56.1 , ≤ 7.56.1 (semver)
    Affected: 7.56.0 , ≤ 7.56.0 (semver)
    Affected: 7.55.1 , ≤ 7.55.1 (semver)
    Affected: 7.55.0 , ≤ 7.55.0 (semver)
    Affected: 7.54.1 , ≤ 7.54.1 (semver)
    Affected: 7.54.0 , ≤ 7.54.0 (semver)
    Affected: 7.53.1 , ≤ 7.53.1 (semver)
    Affected: 7.53.0 , ≤ 7.53.0 (semver)
    Affected: 7.52.1 , ≤ 7.52.1 (semver)
    Affected: 7.52.0 , ≤ 7.52.0 (semver)
    Affected: 7.51.0 , ≤ 7.51.0 (semver)
    Affected: 7.50.3 , ≤ 7.50.3 (semver)
    Affected: 7.50.2 , ≤ 7.50.2 (semver)
    Affected: 7.50.1 , ≤ 7.50.1 (semver)
    Affected: 7.50.0 , ≤ 7.50.0 (semver)
    Affected: 7.49.1 , ≤ 7.49.1 (semver)
    Affected: 7.49.0 , ≤ 7.49.0 (semver)
    Affected: 7.48.0 , ≤ 7.48.0 (semver)
    Affected: 7.47.1 , ≤ 7.47.1 (semver)
    Affected: 7.47.0 , ≤ 7.47.0 (semver)
    Affected: 7.46.0 , ≤ 7.46.0 (semver)
    Affected: 7.45.0 , ≤ 7.45.0 (semver)
    Affected: 7.44.0 , ≤ 7.44.0 (semver)
    Affected: 7.43.0 , ≤ 7.43.0 (semver)
    Affected: 7.42.1 , ≤ 7.42.1 (semver)
    Affected: 7.42.0 , ≤ 7.42.0 (semver)
    Affected: 7.41.0 , ≤ 7.41.0 (semver)
    Affected: 7.40.0 , ≤ 7.40.0 (semver)
    Affected: 7.39.0 , ≤ 7.39.0 (semver)
    Affected: 7.38.0 , ≤ 7.38.0 (semver)
    Affected: 7.37.1 , ≤ 7.37.1 (semver)
    Affected: 7.37.0 , ≤ 7.37.0 (semver)
    Affected: 7.36.0 , ≤ 7.36.0 (semver)
    Affected: 7.35.0 , ≤ 7.35.0 (semver)
    Affected: 7.34.0 , ≤ 7.34.0 (semver)
    Affected: 7.33.0 , ≤ 7.33.0 (semver)
    Affected: 7.32.0 , ≤ 7.32.0 (semver)
    Affected: 7.31.0 , ≤ 7.31.0 (semver)
    Affected: 7.30.0 , ≤ 7.30.0 (semver)
    Affected: 7.29.0 , ≤ 7.29.0 (semver)
    Affected: 7.28.1 , ≤ 7.28.1 (semver)
    Affected: 7.28.0 , ≤ 7.28.0 (semver)
    Affected: 7.27.0 , ≤ 7.27.0 (semver)
    Affected: 7.26.0 , ≤ 7.26.0 (semver)
    Affected: 7.25.0 , ≤ 7.25.0 (semver)
    Affected: 7.24.0 , ≤ 7.24.0 (semver)
    Affected: 7.23.1 , ≤ 7.23.1 (semver)
    Affected: 7.23.0 , ≤ 7.23.0 (semver)
    Affected: 7.22.0 , ≤ 7.22.0 (semver)
    Affected: 7.21.7 , ≤ 7.21.7 (semver)
    Affected: 7.21.6 , ≤ 7.21.6 (semver)
    Affected: 7.21.5 , ≤ 7.21.5 (semver)
    Affected: 7.21.4 , ≤ 7.21.4 (semver)
    Affected: 7.21.3 , ≤ 7.21.3 (semver)
    Affected: 7.21.2 , ≤ 7.21.2 (semver)
    Affected: 7.21.1 , ≤ 7.21.1 (semver)
    Affected: 7.21.0 , ≤ 7.21.0 (semver)
    Affected: 7.20.1 , ≤ 7.20.1 (semver)
    Affected: 7.20.0 , ≤ 7.20.0 (semver)
    Affected: 7.19.7 , ≤ 7.19.7 (semver)
    Affected: 7.19.6 , ≤ 7.19.6 (semver)
    Affected: 7.19.5 , ≤ 7.19.5 (semver)
    Affected: 7.19.4 , ≤ 7.19.4 (semver)
    Affected: 7.19.3 , ≤ 7.19.3 (semver)
    Affected: 7.19.2 , ≤ 7.19.2 (semver)
    Affected: 7.19.1 , ≤ 7.19.1 (semver)
    Affected: 7.19.0 , ≤ 7.19.0 (semver)
    Affected: 7.18.2 , ≤ 7.18.2 (semver)
    Affected: 7.18.1 , ≤ 7.18.1 (semver)
    Affected: 7.18.0 , ≤ 7.18.0 (semver)
    Affected: 7.17.1 , ≤ 7.17.1 (semver)
    Affected: 7.17.0 , ≤ 7.17.0 (semver)
    Affected: 7.16.4 , ≤ 7.16.4 (semver)
    Affected: 7.16.3 , ≤ 7.16.3 (semver)
    Affected: 7.16.2 , ≤ 7.16.2 (semver)
    Affected: 7.16.1 , ≤ 7.16.1 (semver)
    Affected: 7.16.0 , ≤ 7.16.0 (semver)
    Affected: 7.15.5 , ≤ 7.15.5 (semver)
    Affected: 7.15.4 , ≤ 7.15.4 (semver)
    Affected: 7.15.3 , ≤ 7.15.3 (semver)
    Affected: 7.15.2 , ≤ 7.15.2 (semver)
    Affected: 7.15.1 , ≤ 7.15.1 (semver)
    Affected: 7.15.0 , ≤ 7.15.0 (semver)
    Affected: 7.14.1 , ≤ 7.14.1 (semver)
    Affected: 7.14.0 , ≤ 7.14.0 (semver)
    Affected: 7.13.2 , ≤ 7.13.2 (semver)
    Affected: 7.13.1 , ≤ 7.13.1 (semver)
    Affected: 7.13.0 , ≤ 7.13.0 (semver)
    Affected: 7.12.3 , ≤ 7.12.3 (semver)
    Affected: 7.12.2 , ≤ 7.12.2 (semver)
    Affected: 7.12.1 , ≤ 7.12.1 (semver)
    Affected: 7.12.0 , ≤ 7.12.0 (semver)
    Affected: 7.11.2 , ≤ 7.11.2 (semver)
    Affected: 7.11.1 , ≤ 7.11.1 (semver)
    Affected: 7.11.0 , ≤ 7.11.0 (semver)
    Affected: 7.10.8 , ≤ 7.10.8 (semver)
    Affected: 7.10.7 , ≤ 7.10.7 (semver)
    Affected: 7.10.6 , ≤ 7.10.6 (semver)
    Affected: 7.10.5 , ≤ 7.10.5 (semver)
    Affected: 7.10.4 , ≤ 7.10.4 (semver)
    Affected: 7.10.3 , ≤ 7.10.3 (semver)
    Affected: 7.10.2 , ≤ 7.10.2 (semver)
    Affected: 7.10.1 , ≤ 7.10.1 (semver)
    Affected: 7.10 , ≤ 7.10 (semver)
    Affected: 7.9.8 , ≤ 7.9.8 (semver)
    Affected: 7.9.7 , ≤ 7.9.7 (semver)
    Affected: 7.9.6 , ≤ 7.9.6 (semver)
    Affected: 7.9.5 , ≤ 7.9.5 (semver)
    Affected: 7.9.4 , ≤ 7.9.4 (semver)
    Affected: 7.9.3 , ≤ 7.9.3 (semver)
    Affected: 7.9.2 , ≤ 7.9.2 (semver)
    Affected: 7.9.1 , ≤ 7.9.1 (semver)
    Affected: 7.9 , ≤ 7.9 (semver)
    Affected: 7.8.1 , ≤ 7.8.1 (semver)
    Affected: 7.8 , ≤ 7.8 (semver)
    Affected: 7.7.3 , ≤ 7.7.3 (semver)
    Affected: 7.7.2 , ≤ 7.7.2 (semver)
    Affected: 7.7.1 , ≤ 7.7.1 (semver)
    Affected: 7.7 , ≤ 7.7 (semver)
    Affected: 7.6.1 , ≤ 7.6.1 (semver)
    Affected: 7.6 , ≤ 7.6 (semver)
    Affected: 7.5.2 , ≤ 7.5.2 (semver)
    Affected: 7.5.1 , ≤ 7.5.1 (semver)
    Affected: 7.5 , ≤ 7.5 (semver)
    Affected: 7.4.2 , ≤ 7.4.2 (semver)
    Affected: 7.4.1 , ≤ 7.4.1 (semver)
    Affected: 7.4 , ≤ 7.4 (semver)
    Affected: 7.3 , ≤ 7.3 (semver)
    Affected: 7.2.1 , ≤ 7.2.1 (semver)
    Affected: 7.2 , ≤ 7.2 (semver)
    Affected: 7.1.1 , ≤ 7.1.1 (semver)
    Affected: 7.1 , ≤ 7.1 (semver)
    Affected: 6.5.2 , ≤ 6.5.2 (semver)
    Affected: 6.5.1 , ≤ 6.5.1 (semver)
    Affected: 6.5 , ≤ 6.5 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2025-11-03T20:36:27.027Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "url": "http://www.openwall.com/lists/oss-security/2024/12/11/1"
              },
              {
                "url": "https://security.netapp.com/advisory/ntap-20250124-0012/"
              },
              {
                "url": "https://security.netapp.com/advisory/ntap-20250131-0003/"
              },
              {
                "url": "https://security.netapp.com/advisory/ntap-20250131-0004/"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "HIGH",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "NONE",
                  "baseScore": 3.4,
                  "baseSeverity": "LOW",
                  "confidentialityImpact": "LOW",
                  "integrityImpact": "NONE",
                  "privilegesRequired": "NONE",
                  "scope": "CHANGED",
                  "userInteraction": "REQUIRED",
                  "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-11053",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-12-15T16:47:42.738403Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-12-15T16:50:59.398Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "curl",
              "vendor": "curl",
              "versions": [
                {
                  "lessThanOrEqual": "8.11.0",
                  "status": "affected",
                  "version": "8.11.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "8.10.1",
                  "status": "affected",
                  "version": "8.10.1",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "8.10.0",
                  "status": "affected",
                  "version": "8.10.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "8.9.1",
                  "status": "affected",
                  "version": "8.9.1",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "8.9.0",
                  "status": "affected",
                  "version": "8.9.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "8.8.0",
                  "status": "affected",
                  "version": "8.8.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "8.7.1",
                  "status": "affected",
                  "version": "8.7.1",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "8.7.0",
                  "status": "affected",
                  "version": "8.7.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "8.6.0",
                  "status": "affected",
                  "version": "8.6.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "8.5.0",
                  "status": "affected",
                  "version": "8.5.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "8.4.0",
                  "status": "affected",
                  "version": "8.4.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "8.3.0",
                  "status": "affected",
                  "version": "8.3.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "8.2.1",
                  "status": "affected",
                  "version": "8.2.1",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "8.2.0",
                  "status": "affected",
                  "version": "8.2.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "8.1.2",
                  "status": "affected",
                  "version": "8.1.2",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "8.1.1",
                  "status": "affected",
                  "version": "8.1.1",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "8.1.0",
                  "status": "affected",
                  "version": "8.1.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "8.0.1",
                  "status": "affected",
                  "version": "8.0.1",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "8.0.0",
                  "status": "affected",
                  "version": "8.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.88.1",
                  "status": "affected",
                  "version": "7.88.1",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.88.0",
                  "status": "affected",
                  "version": "7.88.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.87.0",
                  "status": "affected",
                  "version": "7.87.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.86.0",
                  "status": "affected",
                  "version": "7.86.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.85.0",
                  "status": "affected",
                  "version": "7.85.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.84.0",
                  "status": "affected",
                  "version": "7.84.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.83.1",
                  "status": "affected",
                  "version": "7.83.1",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.83.0",
                  "status": "affected",
                  "version": "7.83.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.82.0",
                  "status": "affected",
                  "version": "7.82.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.81.0",
                  "status": "affected",
                  "version": "7.81.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.80.0",
                  "status": "affected",
                  "version": "7.80.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.79.1",
                  "status": "affected",
                  "version": "7.79.1",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.79.0",
                  "status": "affected",
                  "version": "7.79.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.78.0",
                  "status": "affected",
                  "version": "7.78.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.77.0",
                  "status": "affected",
                  "version": "7.77.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.76.1",
                  "status": "affected",
                  "version": "7.76.1",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.76.0",
                  "status": "affected",
                  "version": "7.76.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.75.0",
                  "status": "affected",
                  "version": "7.75.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.74.0",
                  "status": "affected",
                  "version": "7.74.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.73.0",
                  "status": "affected",
                  "version": "7.73.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.72.0",
                  "status": "affected",
                  "version": "7.72.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.71.1",
                  "status": "affected",
                  "version": "7.71.1",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.71.0",
                  "status": "affected",
                  "version": "7.71.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.70.0",
                  "status": "affected",
                  "version": "7.70.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.69.1",
                  "status": "affected",
                  "version": "7.69.1",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.69.0",
                  "status": "affected",
                  "version": "7.69.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.68.0",
                  "status": "affected",
                  "version": "7.68.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.67.0",
                  "status": "affected",
                  "version": "7.67.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.66.0",
                  "status": "affected",
                  "version": "7.66.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.65.3",
                  "status": "affected",
                  "version": "7.65.3",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.65.2",
                  "status": "affected",
                  "version": "7.65.2",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.65.1",
                  "status": "affected",
                  "version": "7.65.1",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.65.0",
                  "status": "affected",
                  "version": "7.65.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.64.1",
                  "status": "affected",
                  "version": "7.64.1",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.64.0",
                  "status": "affected",
                  "version": "7.64.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.63.0",
                  "status": "affected",
                  "version": "7.63.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.62.0",
                  "status": "affected",
                  "version": "7.62.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.61.1",
                  "status": "affected",
                  "version": "7.61.1",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.61.0",
                  "status": "affected",
                  "version": "7.61.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.60.0",
                  "status": "affected",
                  "version": "7.60.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.59.0",
                  "status": "affected",
                  "version": "7.59.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.58.0",
                  "status": "affected",
                  "version": "7.58.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.57.0",
                  "status": "affected",
                  "version": "7.57.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.56.1",
                  "status": "affected",
                  "version": "7.56.1",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.56.0",
                  "status": "affected",
                  "version": "7.56.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.55.1",
                  "status": "affected",
                  "version": "7.55.1",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.55.0",
                  "status": "affected",
                  "version": "7.55.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.54.1",
                  "status": "affected",
                  "version": "7.54.1",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.54.0",
                  "status": "affected",
                  "version": "7.54.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.53.1",
                  "status": "affected",
                  "version": "7.53.1",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.53.0",
                  "status": "affected",
                  "version": "7.53.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.52.1",
                  "status": "affected",
                  "version": "7.52.1",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.52.0",
                  "status": "affected",
                  "version": "7.52.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.51.0",
                  "status": "affected",
                  "version": "7.51.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.50.3",
                  "status": "affected",
                  "version": "7.50.3",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.50.2",
                  "status": "affected",
                  "version": "7.50.2",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.50.1",
                  "status": "affected",
                  "version": "7.50.1",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.50.0",
                  "status": "affected",
                  "version": "7.50.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.49.1",
                  "status": "affected",
                  "version": "7.49.1",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.49.0",
                  "status": "affected",
                  "version": "7.49.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.48.0",
                  "status": "affected",
                  "version": "7.48.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.47.1",
                  "status": "affected",
                  "version": "7.47.1",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.47.0",
                  "status": "affected",
                  "version": "7.47.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.46.0",
                  "status": "affected",
                  "version": "7.46.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.45.0",
                  "status": "affected",
                  "version": "7.45.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.44.0",
                  "status": "affected",
                  "version": "7.44.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.43.0",
                  "status": "affected",
                  "version": "7.43.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.42.1",
                  "status": "affected",
                  "version": "7.42.1",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.42.0",
                  "status": "affected",
                  "version": "7.42.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.41.0",
                  "status": "affected",
                  "version": "7.41.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.40.0",
                  "status": "affected",
                  "version": "7.40.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.39.0",
                  "status": "affected",
                  "version": "7.39.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.38.0",
                  "status": "affected",
                  "version": "7.38.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.37.1",
                  "status": "affected",
                  "version": "7.37.1",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.37.0",
                  "status": "affected",
                  "version": "7.37.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.36.0",
                  "status": "affected",
                  "version": "7.36.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.35.0",
                  "status": "affected",
                  "version": "7.35.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.34.0",
                  "status": "affected",
                  "version": "7.34.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.33.0",
                  "status": "affected",
                  "version": "7.33.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.32.0",
                  "status": "affected",
                  "version": "7.32.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.31.0",
                  "status": "affected",
                  "version": "7.31.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.30.0",
                  "status": "affected",
                  "version": "7.30.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.29.0",
                  "status": "affected",
                  "version": "7.29.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.28.1",
                  "status": "affected",
                  "version": "7.28.1",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.28.0",
                  "status": "affected",
                  "version": "7.28.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.27.0",
                  "status": "affected",
                  "version": "7.27.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.26.0",
                  "status": "affected",
                  "version": "7.26.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.25.0",
                  "status": "affected",
                  "version": "7.25.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.24.0",
                  "status": "affected",
                  "version": "7.24.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.23.1",
                  "status": "affected",
                  "version": "7.23.1",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.23.0",
                  "status": "affected",
                  "version": "7.23.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.22.0",
                  "status": "affected",
                  "version": "7.22.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.21.7",
                  "status": "affected",
                  "version": "7.21.7",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.21.6",
                  "status": "affected",
                  "version": "7.21.6",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.21.5",
                  "status": "affected",
                  "version": "7.21.5",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.21.4",
                  "status": "affected",
                  "version": "7.21.4",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.21.3",
                  "status": "affected",
                  "version": "7.21.3",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.21.2",
                  "status": "affected",
                  "version": "7.21.2",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.21.1",
                  "status": "affected",
                  "version": "7.21.1",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.21.0",
                  "status": "affected",
                  "version": "7.21.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.20.1",
                  "status": "affected",
                  "version": "7.20.1",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.20.0",
                  "status": "affected",
                  "version": "7.20.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.19.7",
                  "status": "affected",
                  "version": "7.19.7",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.19.6",
                  "status": "affected",
                  "version": "7.19.6",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.19.5",
                  "status": "affected",
                  "version": "7.19.5",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.19.4",
                  "status": "affected",
                  "version": "7.19.4",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.19.3",
                  "status": "affected",
                  "version": "7.19.3",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.19.2",
                  "status": "affected",
                  "version": "7.19.2",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.19.1",
                  "status": "affected",
                  "version": "7.19.1",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.19.0",
                  "status": "affected",
                  "version": "7.19.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.18.2",
                  "status": "affected",
                  "version": "7.18.2",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.18.1",
                  "status": "affected",
                  "version": "7.18.1",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.18.0",
                  "status": "affected",
                  "version": "7.18.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.17.1",
                  "status": "affected",
                  "version": "7.17.1",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.17.0",
                  "status": "affected",
                  "version": "7.17.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.16.4",
                  "status": "affected",
                  "version": "7.16.4",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.16.3",
                  "status": "affected",
                  "version": "7.16.3",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.16.2",
                  "status": "affected",
                  "version": "7.16.2",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.16.1",
                  "status": "affected",
                  "version": "7.16.1",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.16.0",
                  "status": "affected",
                  "version": "7.16.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.15.5",
                  "status": "affected",
                  "version": "7.15.5",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.15.4",
                  "status": "affected",
                  "version": "7.15.4",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.15.3",
                  "status": "affected",
                  "version": "7.15.3",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.15.2",
                  "status": "affected",
                  "version": "7.15.2",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.15.1",
                  "status": "affected",
                  "version": "7.15.1",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.15.0",
                  "status": "affected",
                  "version": "7.15.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.14.1",
                  "status": "affected",
                  "version": "7.14.1",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.14.0",
                  "status": "affected",
                  "version": "7.14.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.13.2",
                  "status": "affected",
                  "version": "7.13.2",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.13.1",
                  "status": "affected",
                  "version": "7.13.1",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.13.0",
                  "status": "affected",
                  "version": "7.13.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.12.3",
                  "status": "affected",
                  "version": "7.12.3",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.12.2",
                  "status": "affected",
                  "version": "7.12.2",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.12.1",
                  "status": "affected",
                  "version": "7.12.1",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.12.0",
                  "status": "affected",
                  "version": "7.12.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.11.2",
                  "status": "affected",
                  "version": "7.11.2",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.11.1",
                  "status": "affected",
                  "version": "7.11.1",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.11.0",
                  "status": "affected",
                  "version": "7.11.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.10.8",
                  "status": "affected",
                  "version": "7.10.8",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.10.7",
                  "status": "affected",
                  "version": "7.10.7",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.10.6",
                  "status": "affected",
                  "version": "7.10.6",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.10.5",
                  "status": "affected",
                  "version": "7.10.5",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.10.4",
                  "status": "affected",
                  "version": "7.10.4",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.10.3",
                  "status": "affected",
                  "version": "7.10.3",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.10.2",
                  "status": "affected",
                  "version": "7.10.2",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.10.1",
                  "status": "affected",
                  "version": "7.10.1",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.10",
                  "status": "affected",
                  "version": "7.10",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.9.8",
                  "status": "affected",
                  "version": "7.9.8",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.9.7",
                  "status": "affected",
                  "version": "7.9.7",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.9.6",
                  "status": "affected",
                  "version": "7.9.6",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.9.5",
                  "status": "affected",
                  "version": "7.9.5",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.9.4",
                  "status": "affected",
                  "version": "7.9.4",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.9.3",
                  "status": "affected",
                  "version": "7.9.3",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.9.2",
                  "status": "affected",
                  "version": "7.9.2",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.9.1",
                  "status": "affected",
                  "version": "7.9.1",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.9",
                  "status": "affected",
                  "version": "7.9",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.8.1",
                  "status": "affected",
                  "version": "7.8.1",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.8",
                  "status": "affected",
                  "version": "7.8",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.7.3",
                  "status": "affected",
                  "version": "7.7.3",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.7.2",
                  "status": "affected",
                  "version": "7.7.2",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.7.1",
                  "status": "affected",
                  "version": "7.7.1",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.7",
                  "status": "affected",
                  "version": "7.7",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.6.1",
                  "status": "affected",
                  "version": "7.6.1",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.6",
                  "status": "affected",
                  "version": "7.6",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.5.2",
                  "status": "affected",
                  "version": "7.5.2",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.5.1",
                  "status": "affected",
                  "version": "7.5.1",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.5",
                  "status": "affected",
                  "version": "7.5",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.4.2",
                  "status": "affected",
                  "version": "7.4.2",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.4.1",
                  "status": "affected",
                  "version": "7.4.1",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.4",
                  "status": "affected",
                  "version": "7.4",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.3",
                  "status": "affected",
                  "version": "7.3",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.2.1",
                  "status": "affected",
                  "version": "7.2.1",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.2",
                  "status": "affected",
                  "version": "7.2",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.1.1",
                  "status": "affected",
                  "version": "7.1.1",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.1",
                  "status": "affected",
                  "version": "7.1",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.5.2",
                  "status": "affected",
                  "version": "6.5.2",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.5.1",
                  "status": "affected",
                  "version": "6.5.1",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.5",
                  "status": "affected",
                  "version": "6.5",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Harry Sintonen"
            },
            {
              "lang": "en",
              "type": "remediation developer",
              "value": "Daniel Stenberg"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "When asked to both use a `.netrc` file for credentials and to follow HTTP\nredirects, curl could leak the password used for the first host to the\nfollowed-to host under certain circumstances.\n\nThis flaw only manifests itself if the netrc file has an entry that matches\nthe redirect target hostname but the entry either omits just the password or\nomits both login and password."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "CWE-200 Exposure of Sensitive Information to an Unauthorized Actor",
                  "lang": "en"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-12-11T07:34:29.539Z",
            "orgId": "2499f714-1537-4658-8207-48ae4bb9eae9",
            "shortName": "curl"
          },
          "references": [
            {
              "name": "json",
              "url": "https://curl.se/docs/CVE-2024-11053.json"
            },
            {
              "name": "www",
              "url": "https://curl.se/docs/CVE-2024-11053.html"
            },
            {
              "name": "issue",
              "url": "https://hackerone.com/reports/2829063"
            }
          ],
          "title": "netrc and redirect credential leak"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "2499f714-1537-4658-8207-48ae4bb9eae9",
        "assignerShortName": "curl",
        "cveId": "CVE-2024-11053",
        "datePublished": "2024-12-11T07:34:29.539Z",
        "dateReserved": "2024-11-09T18:41:55.703Z",
        "dateUpdated": "2025-11-03T20:36:27.027Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2024-8932 (GCVE-0-2024-8932)

    Vulnerability from cvelistv5 – Published: 2024-11-22 06:03 – Updated: 2025-11-03 22:33
    VLAI
    Title
    OOB access in ldap_escape
    Summary
    In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, uncontrolled long string inputs to ldap_escape() function on 32-bit systems can cause an integer overflow, resulting in an out-of-bounds write.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-11-26 00:00 UTC
    CWE
    Impacted products
    Vendor Product Version
    PHP Group PHP Affected: 8.1.* , < 8.1.31 (semver)
    Affected: 8.2.* , < 8.2.26 (semver)
    Affected: 8.3.* , < 8.3.14 (semver)
    Create a notification for this product.
    php_group php Affected: 8.1.0 , < 8.1.31 (custom)
    Affected: 8.2.0 , < 8.2.26 (custom)
    Affected: 8.3.0 , < 8.3.14 (custom)
        cpe:2.3:a:php_group:php:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2024-11-21 18:15
    Credits
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:php_group:php:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "php",
                "vendor": "php_group",
                "versions": [
                  {
                    "lessThan": "8.1.31",
                    "status": "affected",
                    "version": "8.1.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "8.2.26",
                    "status": "affected",
                    "version": "8.2.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "8.3.14",
                    "status": "affected",
                    "version": "8.3.0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-8932",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-11-26T00:00:00+00:00",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-11-27T04:55:17.998Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2025-11-03T22:33:12.327Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "url": "https://security.netapp.com/advisory/ntap-20250110-0009/"
              },
              {
                "url": "https://lists.debian.org/debian-lts-announce/2024/12/msg00007.html"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "affected",
              "modules": [
                "ldap"
              ],
              "platforms": [
                "32 bit"
              ],
              "product": "PHP",
              "vendor": "PHP Group",
              "versions": [
                {
                  "lessThan": "8.1.31",
                  "status": "affected",
                  "version": "8.1.*",
                  "versionType": "semver"
                },
                {
                  "lessThan": "8.2.26",
                  "status": "affected",
                  "version": "8.2.*",
                  "versionType": "semver"
                },
                {
                  "lessThan": "8.3.14",
                  "status": "affected",
                  "version": "8.3.*",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "Yiheng Cao"
            }
          ],
          "datePublic": "2024-11-21T18:15:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eIn PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, uncontrolled long string inputs to \u003c/span\u003e\u003ccode\u003eldap_escape()\u003c/code\u003e\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003e\u0026nbsp;function on 32-bit systems can cause an integer overflow, resulting in an out-of-bounds write.\u003c/span\u003e\u003cbr\u003e"
                }
              ],
              "value": "In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, uncontrolled long string inputs to ldap_escape()\u00a0function on 32-bit systems can cause an integer overflow, resulting in an out-of-bounds write."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 9.8,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-787",
                  "description": "CWE-787 Out-of-bounds Write",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-11-22T06:03:29.764Z",
            "orgId": "dd77f84a-d19a-4638-8c3d-a322d820ed2b",
            "shortName": "php"
          },
          "references": [
            {
              "url": "https://github.com/php/php-src/security/advisories/GHSA-g665-fm4p-vhff"
            }
          ],
          "source": {
            "advisory": "https://github.com/php/php-src/security/advisories/GHSA-g665-fm4",
            "discovery": "EXTERNAL"
          },
          "title": "OOB access in ldap_escape",
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "dd77f84a-d19a-4638-8c3d-a322d820ed2b",
        "assignerShortName": "php",
        "cveId": "CVE-2024-8932",
        "datePublished": "2024-11-22T06:03:29.764Z",
        "dateReserved": "2024-09-17T04:50:14.830Z",
        "dateUpdated": "2025-11-03T22:33:12.327Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2024-39573 (GCVE-0-2024-39573)

    Vulnerability from cvelistv5 – Published: 2024-07-01 18:16 – Updated: 2025-11-03 21:56
    VLAI
    Title
    Apache HTTP Server: mod_rewrite proxy handler substitution
    Summary
    Potential SSRF in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to cause unsafe RewriteRules to unexpectedly setup URL's to be handled by mod_proxy. Users are recommended to upgrade to version 2.4.60, which fixes this issue.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-07-01 20:41 UTC
    CWE
    • CWE-20 - Improper Input Validation
    Impacted products
    Vendor Product Version
    Apache Software Foundation Apache HTTP Server Affected: 2.4.0 , ≤ 2.4.59 (semver)
    Create a notification for this product.
    apache http_server Affected: 2.4.0 , ≤ 2.4.59 (custom)
        cpe:2.3:a:apache:http_server:-:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:apache:http_server:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "http_server",
                "vendor": "apache",
                "versions": [
                  {
                    "lessThanOrEqual": "2.4.59",
                    "status": "affected",
                    "version": "2.4.0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "NONE",
                  "baseScore": 7.5,
                  "baseSeverity": "HIGH",
                  "confidentialityImpact": "HIGH",
                  "integrityImpact": "NONE",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-39573",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-07-01T20:41:48.835121Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-07-01T20:44:44.754Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2025-11-03T21:56:32.361Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "vendor-advisory",
                  "x_transferred"
                ],
                "url": "https://httpd.apache.org/security/vulnerabilities_24.html"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://security.netapp.com/advisory/ntap-20240712-0001/"
              },
              {
                "url": "http://www.openwall.com/lists/oss-security/2024/07/01/11"
              },
              {
                "url": "http://seclists.org/fulldisclosure/2024/Oct/11"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Apache HTTP Server",
              "vendor": "Apache Software Foundation",
              "versions": [
                {
                  "lessThanOrEqual": "2.4.59",
                  "status": "affected",
                  "version": "2.4.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Orange Tsai (@orange_8361) from DEVCORE"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Potential SSRF in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to cause unsafe RewriteRules to unexpectedly setup URL\u0027s to be handled by mod_proxy.\u003cbr\u003eUsers are recommended to upgrade to version 2.4.60, which fixes this issue."
                }
              ],
              "value": "Potential SSRF in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to cause unsafe RewriteRules to unexpectedly setup URL\u0027s to be handled by mod_proxy.\nUsers are recommended to upgrade to version 2.4.60, which fixes this issue."
            }
          ],
          "metrics": [
            {
              "other": {
                "content": {
                  "text": "moderate"
                },
                "type": "Textual description of severity"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-20",
                  "description": "CWE-20 Improper Input Validation",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-07-12T14:06:16.201Z",
            "orgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
            "shortName": "apache"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://httpd.apache.org/security/vulnerabilities_24.html"
            },
            {
              "url": "https://security.netapp.com/advisory/ntap-20240712-0001/"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "timeline": [
            {
              "lang": "en",
              "time": "2024-04-01T12:00:00.000Z",
              "value": "reported"
            }
          ],
          "title": "Apache HTTP Server: mod_rewrite proxy handler substitution",
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
        "assignerShortName": "apache",
        "cveId": "CVE-2024-39573",
        "datePublished": "2024-07-01T18:16:44.297Z",
        "dateReserved": "2024-06-25T17:13:46.679Z",
        "dateUpdated": "2025-11-03T21:56:32.361Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CERTFR-2025-AVI-1065

    Vulnerability from certfr_avis - Published: 2025-12-05 - Updated: 2025-12-05

    De multiples vulnérabilités ont été découvertes dans NetApp ONTAP. Certaines d'entre elles permettent à un attaquant de provoquer un déni de service à distance, une atteinte à la confidentialité des données et une atteinte à l'intégrité des données.

    Solutions

    Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

    Impacted products
    Vendor Product Description
    NetApp ONTAP ONTAP versions 9.13.x antérieures à 9.13.1P18
    NetApp ONTAP ONTAP versions 9.16.x antérieures à 9.16.1P9
    NetApp ONTAP ONTAP versions 9.14.x antérieures à 9.14.1P15
    NetApp ONTAP ONTAP versions 9.17.x antérieures à 9.17.1P1
    NetApp ONTAP tools pour VMware vSphere 10 ONTAP tools pour VMware vSphere 10 versions antérieures à 10.4
    NetApp ONTAP ONTAP versions 9.15.x antérieures à 9.15.1P13
    References

    Show details on source website

    {
      "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
      "affected_systems": [
        {
          "description": "ONTAP versions 9.13.x ant\u00e9rieures \u00e0 9.13.1P18",
          "product": {
            "name": "ONTAP",
            "vendor": {
              "name": "NetApp",
              "scada": false
            }
          }
        },
        {
          "description": "ONTAP versions 9.16.x ant\u00e9rieures \u00e0 9.16.1P9",
          "product": {
            "name": "ONTAP",
            "vendor": {
              "name": "NetApp",
              "scada": false
            }
          }
        },
        {
          "description": "ONTAP versions 9.14.x ant\u00e9rieures \u00e0 9.14.1P15",
          "product": {
            "name": "ONTAP",
            "vendor": {
              "name": "NetApp",
              "scada": false
            }
          }
        },
        {
          "description": "ONTAP versions 9.17.x ant\u00e9rieures \u00e0 9.17.1P1",
          "product": {
            "name": "ONTAP",
            "vendor": {
              "name": "NetApp",
              "scada": false
            }
          }
        },
        {
          "description": "ONTAP tools pour VMware vSphere 10 versions ant\u00e9rieures \u00e0 10.4",
          "product": {
            "name": "ONTAP tools pour VMware vSphere 10",
            "vendor": {
              "name": "NetApp",
              "scada": false
            }
          }
        },
        {
          "description": "ONTAP versions 9.15.x ant\u00e9rieures \u00e0 9.15.1P13",
          "product": {
            "name": "ONTAP",
            "vendor": {
              "name": "NetApp",
              "scada": false
            }
          }
        }
      ],
      "affected_systems_content": "",
      "content": "## Solutions\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des correctifs (cf. section Documentation).",
      "cves": [
        {
          "name": "CVE-2025-23048",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-23048"
        },
        {
          "name": "CVE-2025-49812",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-49812"
        },
        {
          "name": "CVE-2024-43204",
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-43204"
        },
        {
          "name": "CVE-2025-53020",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-53020"
        },
        {
          "name": "CVE-2024-47252",
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-47252"
        },
        {
          "name": "CVE-2024-55549",
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-55549"
        },
        {
          "name": "CVE-2025-24855",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-24855"
        },
        {
          "name": "CVE-2025-49630",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-49630"
        },
        {
          "name": "CVE-2024-42516",
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-42516"
        },
        {
          "name": "CVE-2024-43394",
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-43394"
        }
      ],
      "initial_release_date": "2025-12-05T00:00:00",
      "last_revision_date": "2025-12-05T00:00:00",
      "links": [],
      "reference": "CERTFR-2025-AVI-1065",
      "revisions": [
        {
          "description": "Version initiale",
          "revision_date": "2025-12-05T00:00:00.000000"
        }
      ],
      "risks": [
        {
          "description": "D\u00e9ni de service \u00e0 distance"
        },
        {
          "description": "Atteinte \u00e0 l\u0027int\u00e9grit\u00e9 des donn\u00e9es"
        },
        {
          "description": "Atteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es"
        }
      ],
      "summary": "De multiples vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 d\u00e9couvertes dans NetApp ONTAP. Certaines d\u0027entre elles permettent \u00e0 un attaquant de provoquer un d\u00e9ni de service \u00e0 distance, une atteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es et une atteinte \u00e0 l\u0027int\u00e9grit\u00e9 des donn\u00e9es.",
      "title": "Multiples vuln\u00e9rabilit\u00e9s dans NetApp ONTAP",
      "vendor_advisories": [
        {
          "published_at": "2025-12-05",
          "title": "Bulletin de s\u00e9curit\u00e9 NetApp NTAP-20250613-0007",
          "url": "https://security.netapp.com/advisory/NTAP-20250613-0007"
        },
        {
          "published_at": "2025-12-05",
          "title": "Bulletin de s\u00e9curit\u00e9 NetApp NTAP-20250613-0006",
          "url": "https://security.netapp.com/advisory/NTAP-20250613-0006"
        },
        {
          "published_at": "2025-12-05",
          "title": "Bulletin de s\u00e9curit\u00e9 NetApp NTAP-20250718-0013",
          "url": "https://security.netapp.com/advisory/NTAP-20250718-0013"
        }
      ]
    }