Search

Find a vulnerability

Search criteria

    Related vulnerabilities

    CLEANSTART-2026-AE16267 (CVE-2025-47912)

    Vulnerability from cleanstart – Published: 2026-09-08 01:48 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    gRPC-Go is the Go language implementation of gRPC
    Details

    Multiple security vulnerabilities affect the step package. gRPC-Go is the Go language implementation of gRPC. See references for individual vulnerability details.

    References
    https://github.com/cleanstart-dev/cleanstart-secu… ADVISORY
    https://osv.dev/vulnerability/CVE-2025-47912 WEB
    https://osv.dev/vulnerability/CVE-2025-58183 WEB
    https://osv.dev/vulnerability/CVE-2025-58185 WEB
    https://osv.dev/vulnerability/CVE-2025-58186 WEB
    https://osv.dev/vulnerability/CVE-2025-58187 WEB
    https://osv.dev/vulnerability/CVE-2025-58188 WEB
    https://osv.dev/vulnerability/CVE-2025-58189 WEB
    https://osv.dev/vulnerability/CVE-2025-61723 WEB
    https://osv.dev/vulnerability/CVE-2025-61724 WEB
    https://osv.dev/vulnerability/CVE-2025-61725 WEB
    https://osv.dev/vulnerability/CVE-2025-61729 WEB
    https://osv.dev/vulnerability/CVE-2025-62820 WEB
    https://osv.dev/vulnerability/CVE-2026-33186 WEB
    https://osv.dev/vulnerability/CVE-2026-33818 WEB
    https://osv.dev/vulnerability/CVE-2026-39821 WEB
    https://osv.dev/vulnerability/CVE-2026-39822 WEB
    https://osv.dev/vulnerability/CVE-2026-42505 WEB
    https://osv.dev/vulnerability/CVE-2026-46600 WEB
    https://osv.dev/vulnerability/CVE-2026-56852 WEB
    https://osv.dev/vulnerability/CVE-2026-56853 WEB
    https://osv.dev/vulnerability/CVE-2026-56855 WEB
    https://osv.dev/vulnerability/CVE-2026-56858 WEB
    https://osv.dev/vulnerability/CVE-2026-56859 WEB
    https://osv.dev/vulnerability/CVE-2026-56860 WEB
    https://osv.dev/vulnerability/CVE-2026-56862 WEB
    https://osv.dev/vulnerability/CVE-2026-78662 WEB
    https://osv.dev/vulnerability/CVE-2026-84304 WEB
    https://osv.dev/vulnerability/ghsa-259r-337f-4rfw WEB
    https://osv.dev/vulnerability/ghsa-hrxh-6v49-42gf WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-47912 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-58183 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-58185 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-58186 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-58187 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-58188 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-58189 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-61723 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-61724 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-61725 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-61729 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-62820 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-33186 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-33818 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39821 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39822 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42505 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-46600 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56852 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56853 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56855 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56858 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56859 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56860 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56862 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-78662 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-84304 WEB

    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "step"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "0.30.6-r5"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Multiple security vulnerabilities affect the step package. gRPC-Go is the Go language implementation of gRPC. See references for individual vulnerability details.",
      "id": "CLEANSTART-2026-AE16267",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-09-08T01:48:50.081347Z",
      "references": [
        {
          "type": "ADVISORY",
          "url": "https://github.com/cleanstart-dev/cleanstart-security-advisories/tree/main/advisories/2026/CLEANSTART-2026-AE16267.json"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-47912"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-58183"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-58185"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-58186"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-58187"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-58188"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-58189"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-61723"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-61724"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-61725"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-61729"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-62820"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-33186"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-33818"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39821"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39822"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42505"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-46600"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56852"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56853"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56855"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56858"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56859"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56860"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56862"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-78662"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-84304"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-259r-337f-4rfw"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-hrxh-6v49-42gf"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47912"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58183"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58185"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58186"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58187"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58188"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58189"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61723"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61724"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61725"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61729"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-62820"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33186"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33818"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39821"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39822"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42505"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46600"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56852"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56853"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56855"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56858"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56859"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56860"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56862"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78662"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84304"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "severity": [
        {
          "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "type": "CVSS_V3"
        }
      ],
      "summary": "gRPC-Go is the Go language implementation of gRPC",
      "upstream": [
        "CVE-2025-47912",
        "CVE-2025-58183",
        "CVE-2025-58185",
        "CVE-2025-58186",
        "CVE-2025-58187",
        "CVE-2025-58188",
        "CVE-2025-58189",
        "CVE-2025-61723",
        "CVE-2025-61724",
        "CVE-2025-61725",
        "CVE-2025-61729",
        "CVE-2025-62820",
        "CVE-2026-33186",
        "CVE-2026-33818",
        "CVE-2026-39821",
        "CVE-2026-39822",
        "CVE-2026-42505",
        "CVE-2026-46600",
        "CVE-2026-56852",
        "CVE-2026-56853",
        "CVE-2026-56855",
        "CVE-2026-56858",
        "CVE-2026-56859",
        "CVE-2026-56860",
        "CVE-2026-56862",
        "CVE-2026-78662",
        "CVE-2026-84304",
        "ghsa-259r-337f-4rfw",
        "ghsa-hrxh-6v49-42gf"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-AH15669 (GHSA-259R-337F-4RFW)

    Vulnerability from cleanstart – Published: 2026-09-30 20:34 – Updated: 2026-08-21 12:59 – Source website
    VLAI
    Summary
    Security fix for ghsa-259r-337f-4rfw applied in: crane 0.19.2-r1, crane 0.20.7-r3, crane 0.20.7-r4
    Details

    ghsa-259r-337f-4rfw affects multiple packages. This issue is resolved in later releases. See references for individual vulnerability details.


    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "crane"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "0.19.2-r1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "crane"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "0.20.7-r3"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "crane"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "0.20.7-r4"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "ghsa-259r-337f-4rfw affects multiple packages. This issue is resolved in later releases. See references for individual vulnerability details.",
      "id": "CLEANSTART-2026-AH15669",
      "modified": "2026-08-21T12:59:12Z",
      "published": "2026-09-30T20:34:53.118246Z",
      "references": [
        {
          "type": "ADVISORY",
          "url": "https://github.com/cleanstart-dev/cleanstart-security-advisories/tree/main/advisories/2026/CLEANSTART-2026-AH15669.json"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-259r-337f-4rfw"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "summary": "Security fix for ghsa-259r-337f-4rfw applied in: crane 0.19.2-r1, crane 0.20.7-r3, crane 0.20.7-r4",
      "upstream": [
        "ghsa-259r-337f-4rfw"
      ]
    }

    CLEANSTART-2026-AJ39907 (CVE-2025-47912)

    Vulnerability from cleanstart – Published: 2026-09-08 01:55 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    gRPC-Go is the Go language implementation of gRPC
    Details

    Multiple security vulnerabilities affect the step package. gRPC-Go is the Go language implementation of gRPC. See references for individual vulnerability details.

    References
    https://github.com/cleanstart-dev/cleanstart-secu… ADVISORY
    https://osv.dev/vulnerability/CVE-2025-47912 WEB
    https://osv.dev/vulnerability/CVE-2025-58183 WEB
    https://osv.dev/vulnerability/CVE-2025-58185 WEB
    https://osv.dev/vulnerability/CVE-2025-58186 WEB
    https://osv.dev/vulnerability/CVE-2025-58187 WEB
    https://osv.dev/vulnerability/CVE-2025-58188 WEB
    https://osv.dev/vulnerability/CVE-2025-58189 WEB
    https://osv.dev/vulnerability/CVE-2025-61723 WEB
    https://osv.dev/vulnerability/CVE-2025-61724 WEB
    https://osv.dev/vulnerability/CVE-2025-61725 WEB
    https://osv.dev/vulnerability/CVE-2025-61729 WEB
    https://osv.dev/vulnerability/CVE-2025-62820 WEB
    https://osv.dev/vulnerability/CVE-2025-69725 WEB
    https://osv.dev/vulnerability/CVE-2026-25793 WEB
    https://osv.dev/vulnerability/CVE-2026-26958 WEB
    https://osv.dev/vulnerability/CVE-2026-29181 WEB
    https://osv.dev/vulnerability/CVE-2026-30836 WEB
    https://osv.dev/vulnerability/CVE-2026-33815 WEB
    https://osv.dev/vulnerability/CVE-2026-33816 WEB
    https://osv.dev/vulnerability/CVE-2026-33818 WEB
    https://osv.dev/vulnerability/CVE-2026-34986 WEB
    https://osv.dev/vulnerability/CVE-2026-39821 WEB
    https://osv.dev/vulnerability/CVE-2026-39822 WEB
    https://osv.dev/vulnerability/CVE-2026-40097 WEB
    https://osv.dev/vulnerability/CVE-2026-41178 WEB
    https://osv.dev/vulnerability/CVE-2026-41889 WEB
    https://osv.dev/vulnerability/CVE-2026-42505 WEB
    https://osv.dev/vulnerability/CVE-2026-46600 WEB
    https://osv.dev/vulnerability/CVE-2026-56853 WEB
    https://osv.dev/vulnerability/CVE-2026-56855 WEB
    https://osv.dev/vulnerability/CVE-2026-56858 WEB
    https://osv.dev/vulnerability/CVE-2026-56859 WEB
    https://osv.dev/vulnerability/CVE-2026-56860 WEB
    https://osv.dev/vulnerability/CVE-2026-56862 WEB
    https://osv.dev/vulnerability/CVE-2026-78662 WEB
    https://osv.dev/vulnerability/CVE-2026-84304 WEB
    https://osv.dev/vulnerability/ghsa-259r-337f-4rfw WEB
    https://osv.dev/vulnerability/ghsa-3fxj-6jh8-hvhx WEB
    https://osv.dev/vulnerability/ghsa-9g5q-2w5x-hmxf WEB
    https://osv.dev/vulnerability/ghsa-hrxh-6v49-42gf WEB
    https://osv.dev/vulnerability/ghsa-mpwr-8vm7-h73f WEB
    https://osv.dev/vulnerability/ghsa-rjr7-jggh-pgcp WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-47912 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-58183 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-58185 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-58186 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-58187 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-58188 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-58189 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-61723 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-61724 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-61725 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-61729 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-62820 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-69725 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-25793 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-26958 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-29181 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-30836 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-33815 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-33816 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-33818 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-34986 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39821 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39822 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-40097 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-41178 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-41889 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42505 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-46600 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56853 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56855 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56858 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56859 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56860 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56862 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-78662 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-84304 WEB

    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "step"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "0.29.0-r5"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Multiple security vulnerabilities affect the step package. gRPC-Go is the Go language implementation of gRPC. See references for individual vulnerability details.",
      "id": "CLEANSTART-2026-AJ39907",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-09-08T01:55:49.714182Z",
      "references": [
        {
          "type": "ADVISORY",
          "url": "https://github.com/cleanstart-dev/cleanstart-security-advisories/tree/main/advisories/2026/CLEANSTART-2026-AJ39907.json"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-47912"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-58183"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-58185"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-58186"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-58187"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-58188"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-58189"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-61723"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-61724"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-61725"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-61729"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-62820"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-69725"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-25793"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-26958"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-29181"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-30836"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-33815"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-33816"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-33818"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-34986"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39821"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39822"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-40097"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-41178"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-41889"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42505"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-46600"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56853"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56855"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56858"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56859"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56860"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56862"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-78662"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-84304"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-259r-337f-4rfw"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-3fxj-6jh8-hvhx"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-9g5q-2w5x-hmxf"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-hrxh-6v49-42gf"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-mpwr-8vm7-h73f"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-rjr7-jggh-pgcp"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47912"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58183"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58185"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58186"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58187"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58188"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58189"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61723"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61724"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61725"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61729"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-62820"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-69725"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25793"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-26958"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-29181"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-30836"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33815"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33816"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33818"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-34986"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39821"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39822"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-40097"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41178"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41889"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42505"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46600"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56853"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56855"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56858"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56859"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56860"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56862"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78662"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84304"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "severity": [
        {
          "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "type": "CVSS_V3"
        }
      ],
      "summary": "gRPC-Go is the Go language implementation of gRPC",
      "upstream": [
        "CVE-2025-47912",
        "CVE-2025-58183",
        "CVE-2025-58185",
        "CVE-2025-58186",
        "CVE-2025-58187",
        "CVE-2025-58188",
        "CVE-2025-58189",
        "CVE-2025-61723",
        "CVE-2025-61724",
        "CVE-2025-61725",
        "CVE-2025-61729",
        "CVE-2025-62820",
        "CVE-2025-69725",
        "CVE-2026-25793",
        "CVE-2026-26958",
        "CVE-2026-29181",
        "CVE-2026-30836",
        "CVE-2026-33815",
        "CVE-2026-33816",
        "CVE-2026-33818",
        "CVE-2026-34986",
        "CVE-2026-39821",
        "CVE-2026-39822",
        "CVE-2026-40097",
        "CVE-2026-41178",
        "CVE-2026-41889",
        "CVE-2026-42505",
        "CVE-2026-46600",
        "CVE-2026-56853",
        "CVE-2026-56855",
        "CVE-2026-56858",
        "CVE-2026-56859",
        "CVE-2026-56860",
        "CVE-2026-56862",
        "CVE-2026-78662",
        "CVE-2026-84304",
        "ghsa-259r-337f-4rfw",
        "ghsa-3fxj-6jh8-hvhx",
        "ghsa-9g5q-2w5x-hmxf",
        "ghsa-hrxh-6v49-42gf",
        "ghsa-mpwr-8vm7-h73f",
        "ghsa-rjr7-jggh-pgcp"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-AJ83096 (CVE-2025-47912)

    Vulnerability from cleanstart – Published: 2026-09-10 01:08 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsing deeply-nested, recursive structures
    Details

    Multiple security vulnerabilities affect the logstash-exporter package. Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsing deeply-nested, recursive structures. See references for individual vulnerability details.

    References
    https://github.com/cleanstart-dev/cleanstart-secu… ADVISORY
    https://osv.dev/vulnerability/CVE-2025-47912 WEB
    https://osv.dev/vulnerability/CVE-2025-58183 WEB
    https://osv.dev/vulnerability/CVE-2025-58185 WEB
    https://osv.dev/vulnerability/CVE-2025-58186 WEB
    https://osv.dev/vulnerability/CVE-2025-58187 WEB
    https://osv.dev/vulnerability/CVE-2025-58188 WEB
    https://osv.dev/vulnerability/CVE-2025-58189 WEB
    https://osv.dev/vulnerability/CVE-2025-61723 WEB
    https://osv.dev/vulnerability/CVE-2025-61724 WEB
    https://osv.dev/vulnerability/CVE-2025-61725 WEB
    https://osv.dev/vulnerability/CVE-2025-61729 WEB
    https://osv.dev/vulnerability/CVE-2025-68121 WEB
    https://osv.dev/vulnerability/CVE-2026-32283 WEB
    https://osv.dev/vulnerability/CVE-2026-33818 WEB
    https://osv.dev/vulnerability/CVE-2026-39820 WEB
    https://osv.dev/vulnerability/CVE-2026-39821 WEB
    https://osv.dev/vulnerability/CVE-2026-39822 WEB
    https://osv.dev/vulnerability/CVE-2026-39824 WEB
    https://osv.dev/vulnerability/CVE-2026-39836 WEB
    https://osv.dev/vulnerability/CVE-2026-42499 WEB
    https://osv.dev/vulnerability/CVE-2026-42505 WEB
    https://osv.dev/vulnerability/CVE-2026-46600 WEB
    https://osv.dev/vulnerability/CVE-2026-56853 WEB
    https://osv.dev/vulnerability/CVE-2026-56858 WEB
    https://osv.dev/vulnerability/CVE-2026-56859 WEB
    https://osv.dev/vulnerability/CVE-2026-56860 WEB
    https://osv.dev/vulnerability/CVE-2026-56862 WEB
    https://osv.dev/vulnerability/ghsa-259r-337f-4rfw WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-47912 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-58183 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-58185 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-58186 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-58187 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-58188 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-58189 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-61723 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-61724 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-61725 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-61729 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-68121 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-32283 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-33818 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39820 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39821 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39822 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39824 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39836 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42499 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42505 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-46600 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56853 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56858 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56859 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56860 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56862 WEB

    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "logstash-exporter"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "1.9.1-r2"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Multiple security vulnerabilities affect the logstash-exporter package. Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsing deeply-nested, recursive structures. See references for individual vulnerability details.",
      "id": "CLEANSTART-2026-AJ83096",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-09-10T01:08:37.435444Z",
      "references": [
        {
          "type": "ADVISORY",
          "url": "https://github.com/cleanstart-dev/cleanstart-security-advisories/tree/main/advisories/2026/CLEANSTART-2026-AJ83096.json"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-47912"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-58183"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-58185"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-58186"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-58187"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-58188"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-58189"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-61723"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-61724"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-61725"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-61729"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-68121"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-32283"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-33818"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39820"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39821"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39822"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39824"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39836"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42499"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42505"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-46600"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56853"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56858"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56859"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56860"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56862"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-259r-337f-4rfw"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47912"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58183"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58185"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58186"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58187"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58188"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58189"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61723"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61724"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61725"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61729"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-68121"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32283"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33818"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39820"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39821"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39822"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39824"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39836"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42499"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42505"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46600"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56853"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56858"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56859"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56860"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56862"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "severity": [
        {
          "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "type": "CVSS_V3"
        }
      ],
      "summary": "Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsing deeply-nested, recursive structures",
      "upstream": [
        "CVE-2025-47912",
        "CVE-2025-58183",
        "CVE-2025-58185",
        "CVE-2025-58186",
        "CVE-2025-58187",
        "CVE-2025-58188",
        "CVE-2025-58189",
        "CVE-2025-61723",
        "CVE-2025-61724",
        "CVE-2025-61725",
        "CVE-2025-61729",
        "CVE-2025-68121",
        "CVE-2026-32283",
        "CVE-2026-33818",
        "CVE-2026-39820",
        "CVE-2026-39821",
        "CVE-2026-39822",
        "CVE-2026-39824",
        "CVE-2026-39836",
        "CVE-2026-42499",
        "CVE-2026-42505",
        "CVE-2026-46600",
        "CVE-2026-56853",
        "CVE-2026-56858",
        "CVE-2026-56859",
        "CVE-2026-56860",
        "CVE-2026-56862",
        "ghsa-259r-337f-4rfw"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-AQ94704 (CVE-2024-51744)

    Vulnerability from cleanstart – Published: 2026-09-15 01:00 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection
    Details

    Multiple security vulnerabilities affect the minio-operator package. Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. See references for individual vulnerability details.

    References
    https://github.com/cleanstart-dev/cleanstart-secu… ADVISORY
    https://osv.dev/vulnerability/CVE-2024-51744 WEB
    https://osv.dev/vulnerability/CVE-2025-30204 WEB
    https://osv.dev/vulnerability/CVE-2025-47912 WEB
    https://osv.dev/vulnerability/CVE-2025-58183 WEB
    https://osv.dev/vulnerability/CVE-2025-58185 WEB
    https://osv.dev/vulnerability/CVE-2025-58186 WEB
    https://osv.dev/vulnerability/CVE-2025-58187 WEB
    https://osv.dev/vulnerability/CVE-2025-58188 WEB
    https://osv.dev/vulnerability/CVE-2025-58189 WEB
    https://osv.dev/vulnerability/CVE-2025-61723 WEB
    https://osv.dev/vulnerability/CVE-2025-61724 WEB
    https://osv.dev/vulnerability/CVE-2025-61725 WEB
    https://osv.dev/vulnerability/CVE-2025-61726 WEB
    https://osv.dev/vulnerability/CVE-2025-61727 WEB
    https://osv.dev/vulnerability/CVE-2025-61728 WEB
    https://osv.dev/vulnerability/CVE-2025-61729 WEB
    https://osv.dev/vulnerability/CVE-2025-61730 WEB
    https://osv.dev/vulnerability/CVE-2025-61731 WEB
    https://osv.dev/vulnerability/CVE-2025-61732 WEB
    https://osv.dev/vulnerability/CVE-2025-68119 WEB
    https://osv.dev/vulnerability/CVE-2025-68121 WEB
    https://osv.dev/vulnerability/CVE-2026-25679 WEB
    https://osv.dev/vulnerability/CVE-2026-25680 WEB
    https://osv.dev/vulnerability/CVE-2026-27139 WEB
    https://osv.dev/vulnerability/CVE-2026-27142 WEB
    https://osv.dev/vulnerability/CVE-2026-27145 WEB
    https://osv.dev/vulnerability/CVE-2026-33814 WEB
    https://osv.dev/vulnerability/CVE-2026-33818 WEB
    https://osv.dev/vulnerability/CVE-2026-39821 WEB
    https://osv.dev/vulnerability/CVE-2026-39833 WEB
    https://osv.dev/vulnerability/CVE-2026-39836 WEB
    https://osv.dev/vulnerability/CVE-2026-42499 WEB
    https://osv.dev/vulnerability/CVE-2026-42504 WEB
    https://osv.dev/vulnerability/CVE-2026-42507 WEB
    https://osv.dev/vulnerability/CVE-2026-42508 WEB
    https://osv.dev/vulnerability/CVE-2026-46595 WEB
    https://osv.dev/vulnerability/CVE-2026-46600 WEB
    https://osv.dev/vulnerability/CVE-2026-56853 WEB
    https://osv.dev/vulnerability/CVE-2026-56855 WEB
    https://osv.dev/vulnerability/CVE-2026-56858 WEB
    https://osv.dev/vulnerability/CVE-2026-56859 WEB
    https://osv.dev/vulnerability/CVE-2026-56860 WEB
    https://osv.dev/vulnerability/CVE-2026-56862 WEB
    https://osv.dev/vulnerability/CVE-2026-56864 WEB
    https://osv.dev/vulnerability/CVE-2026-56865 WEB
    https://osv.dev/vulnerability/CVE-2026-78662 WEB
    https://osv.dev/vulnerability/ghsa-259r-337f-4rfw WEB
    https://osv.dev/vulnerability/ghsa-29wx-vh33-7x7r WEB
    https://osv.dev/vulnerability/ghsa-f6x5-jh6r-wrfv WEB
    https://osv.dev/vulnerability/ghsa-j5w8-q4qc-rx2x WEB
    https://osv.dev/vulnerability/ghsa-mh63-6h87-95cp WEB
    https://osv.dev/vulnerability/ghsa-p436-gjf2-799p WEB
    https://nvd.nist.gov/vuln/detail/CVE-2024-51744 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-30204 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-47912 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-58183 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-58185 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-58186 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-58187 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-58188 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-58189 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-61723 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-61724 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-61725 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-61726 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-61727 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-61728 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-61729 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-61730 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-61731 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-61732 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-68119 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-68121 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-25679 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-25680 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-27139 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-27142 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-27145 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-33814 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-33818 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39821 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39833 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39836 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42499 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42504 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42507 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42508 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-46595 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-46600 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56853 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56855 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56858 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56859 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56860 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56862 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56864 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56865 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-78662 WEB

    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "minio-operator"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "7.1.1-r5"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Multiple security vulnerabilities affect the minio-operator package. Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. See references for individual vulnerability details.",
      "id": "CLEANSTART-2026-AQ94704",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-09-15T01:00:17.233996Z",
      "references": [
        {
          "type": "ADVISORY",
          "url": "https://github.com/cleanstart-dev/cleanstart-security-advisories/tree/main/advisories/2026/CLEANSTART-2026-AQ94704.json"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2024-51744"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-30204"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-47912"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-58183"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-58185"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-58186"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-58187"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-58188"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-58189"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-61723"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-61724"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-61725"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-61726"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-61727"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-61728"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-61729"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-61730"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-61731"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-61732"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-68119"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-68121"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-25679"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-25680"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-27139"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-27142"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-27145"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-33814"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-33818"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39821"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39833"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39836"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42499"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42504"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42507"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42508"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-46595"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-46600"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56853"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56855"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56858"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56859"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56860"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56862"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56864"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56865"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-78662"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-259r-337f-4rfw"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-29wx-vh33-7x7r"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-f6x5-jh6r-wrfv"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-j5w8-q4qc-rx2x"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-mh63-6h87-95cp"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-p436-gjf2-799p"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51744"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30204"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47912"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58183"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58185"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58186"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58187"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58188"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58189"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61723"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61724"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61725"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61726"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61727"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61728"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61729"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61730"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61731"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61732"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-68119"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-68121"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25679"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25680"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27139"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27142"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27145"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33814"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33818"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39821"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39833"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39836"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42499"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42504"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42507"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42508"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46595"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46600"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56853"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56855"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56858"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56859"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56860"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56862"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56864"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56865"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78662"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "severity": [
        {
          "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "type": "CVSS_V3"
        }
      ],
      "summary": "Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection",
      "upstream": [
        "CVE-2024-51744",
        "CVE-2025-30204",
        "CVE-2025-47912",
        "CVE-2025-58183",
        "CVE-2025-58185",
        "CVE-2025-58186",
        "CVE-2025-58187",
        "CVE-2025-58188",
        "CVE-2025-58189",
        "CVE-2025-61723",
        "CVE-2025-61724",
        "CVE-2025-61725",
        "CVE-2025-61726",
        "CVE-2025-61727",
        "CVE-2025-61728",
        "CVE-2025-61729",
        "CVE-2025-61730",
        "CVE-2025-61731",
        "CVE-2025-61732",
        "CVE-2025-68119",
        "CVE-2025-68121",
        "CVE-2026-25679",
        "CVE-2026-25680",
        "CVE-2026-27139",
        "CVE-2026-27142",
        "CVE-2026-27145",
        "CVE-2026-33814",
        "CVE-2026-33818",
        "CVE-2026-39821",
        "CVE-2026-39833",
        "CVE-2026-39836",
        "CVE-2026-42499",
        "CVE-2026-42504",
        "CVE-2026-42507",
        "CVE-2026-42508",
        "CVE-2026-46595",
        "CVE-2026-46600",
        "CVE-2026-56853",
        "CVE-2026-56855",
        "CVE-2026-56858",
        "CVE-2026-56859",
        "CVE-2026-56860",
        "CVE-2026-56862",
        "CVE-2026-56864",
        "CVE-2026-56865",
        "CVE-2026-78662",
        "ghsa-259r-337f-4rfw",
        "ghsa-29wx-vh33-7x7r",
        "ghsa-f6x5-jh6r-wrfv",
        "ghsa-j5w8-q4qc-rx2x",
        "ghsa-mh63-6h87-95cp",
        "ghsa-p436-gjf2-799p"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-AT65598 (GHSA-HRXH-6V49-42GF)

    Vulnerability from cleanstart – Published: 2026-07-30 07:10 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    Security fixes in rclone 1.74.3-r2
    Details

    Package rclone version 1.74.3-r2 fixes 5 vulnerabilities: ghsa-hrxh-6v49-42gf, ghsa-259r-337f-4rfw, ghsa-3fxj-6jh8-hvhx, ghsa-9g5q-2w5x-hmxf, ghsa-rjr7-jggh-pgcp

    References

    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "rclone"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "1.74.3-r2"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "1.74.3-r2"
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Package rclone version 1.74.3-r2 fixes 5 vulnerabilities: ghsa-hrxh-6v49-42gf, ghsa-259r-337f-4rfw, ghsa-3fxj-6jh8-hvhx, ghsa-9g5q-2w5x-hmxf, ghsa-rjr7-jggh-pgcp",
      "id": "CLEANSTART-2026-AT65598",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-07-30T07:10:53Z",
      "references": [
        {
          "type": "WEB",
          "url": "https://github.com/rclone/rclone"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "summary": "Security fixes in rclone 1.74.3-r2",
      "upstream": [
        "ghsa-hrxh-6v49-42gf",
        "ghsa-259r-337f-4rfw",
        "ghsa-3fxj-6jh8-hvhx",
        "ghsa-9g5q-2w5x-hmxf",
        "ghsa-rjr7-jggh-pgcp"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-AW13171 (GHSA-HRXH-6V49-42GF)

    Vulnerability from cleanstart – Published: 2026-07-30 07:10 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    Security fixes in rclone 1.72.1-r11
    Details

    Package rclone version 1.72.1-r11 fixes 5 vulnerabilities: ghsa-hrxh-6v49-42gf, ghsa-259r-337f-4rfw, ghsa-3fxj-6jh8-hvhx, ghsa-9g5q-2w5x-hmxf, ghsa-rjr7-jggh-pgcp

    References

    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "rclone"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "1.72.1-r11"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "1.72.1-r11"
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Package rclone version 1.72.1-r11 fixes 5 vulnerabilities: ghsa-hrxh-6v49-42gf, ghsa-259r-337f-4rfw, ghsa-3fxj-6jh8-hvhx, ghsa-9g5q-2w5x-hmxf, ghsa-rjr7-jggh-pgcp",
      "id": "CLEANSTART-2026-AW13171",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-07-30T07:10:53Z",
      "references": [
        {
          "type": "WEB",
          "url": "https://github.com/rclone/rclone"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "summary": "Security fixes in rclone 1.72.1-r11",
      "upstream": [
        "ghsa-hrxh-6v49-42gf",
        "ghsa-259r-337f-4rfw",
        "ghsa-3fxj-6jh8-hvhx",
        "ghsa-9g5q-2w5x-hmxf",
        "ghsa-rjr7-jggh-pgcp"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-AW19890 (GHSA-259R-337F-4RFW)

    Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    Security fixes in prometheus-statsd-exporter 0.27.2-r1
    Details

    Package prometheus-statsd-exporter version 0.27.2-r1 fixes 10 vulnerabilities: ghsa-259r-337f-4rfw, CVE-2026-39821, CVE-2026-56860, CVE-2026-56858, CVE-2026-33818...


    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "prometheus-statsd-exporter"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "0.27.2-r1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "0.27.2-r1"
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Package prometheus-statsd-exporter version 0.27.2-r1 fixes 10 vulnerabilities: ghsa-259r-337f-4rfw, CVE-2026-39821, CVE-2026-56860, CVE-2026-56858, CVE-2026-33818...",
      "id": "CLEANSTART-2026-AW19890",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-09-01T11:17:16Z",
      "references": [
        {
          "type": "WEB",
          "url": "https://github.com/prometheus/statsd_exporter"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "summary": "Security fixes in prometheus-statsd-exporter 0.27.2-r1",
      "upstream": [
        "ghsa-259r-337f-4rfw",
        "CVE-2026-39821",
        "CVE-2026-56860",
        "CVE-2026-56858",
        "CVE-2026-33818",
        "CVE-2026-46600",
        "CVE-2026-56853",
        "CVE-2026-56859",
        "CVE-2026-56862",
        "CVE-2026-39821"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-AY98693 (GHSA-259R-337F-4RFW)

    Vulnerability from cleanstart – Published: 2026-07-30 07:10 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    Security fixes in elastic-beats 9.2.8-r7
    Details

    Package elastic-beats version 9.2.8-r7 fixes 2 vulnerabilities: ghsa-259r-337f-4rfw, CVE-2026-41178

    References

    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "elastic-beats"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "9.2.8-r7"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "9.2.8-r7"
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Package elastic-beats version 9.2.8-r7 fixes 2 vulnerabilities: ghsa-259r-337f-4rfw, CVE-2026-41178",
      "id": "CLEANSTART-2026-AY98693",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-07-30T07:10:53Z",
      "references": [
        {
          "type": "WEB",
          "url": "https://www.elastic.co/products/beats"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "summary": "Security fixes in elastic-beats 9.2.8-r7",
      "upstream": [
        "ghsa-259r-337f-4rfw",
        "CVE-2026-41178"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-BA26255 (CVE-2026-26958)

    Vulnerability from cleanstart – Published: 2026-09-10 01:49 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    filippo
    Details

    Multiple security vulnerabilities affect the dex package. filippo. See references for individual vulnerability details.


    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "dex"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "2.42.1-r2"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Multiple security vulnerabilities affect the dex package. filippo. See references for individual vulnerability details.",
      "id": "CLEANSTART-2026-BA26255",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-09-10T01:49:39.942504Z",
      "references": [
        {
          "type": "ADVISORY",
          "url": "https://github.com/cleanstart-dev/cleanstart-security-advisories/tree/main/advisories/2026/CLEANSTART-2026-BA26255.json"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-26958"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-259r-337f-4rfw"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-fw7p-63qq-7hpr"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-26958"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "summary": "filippo",
      "upstream": [
        "CVE-2026-26958",
        "ghsa-259r-337f-4rfw",
        "ghsa-fw7p-63qq-7hpr"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-BB29139 (GHSA-259R-337F-4RFW)

    Vulnerability from cleanstart – Published: 2026-08-13 12:10 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    Security fixes in rabbitmq-messaging-topology-operator 1.16.0-r2
    Details

    Package rabbitmq-messaging-topology-operator version 1.16.0-r2 fixes 1 vulnerabilities: ghsa-259r-337f-4rfw


    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "rabbitmq-messaging-topology-operator"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "1.16.0-r2"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "1.16.0-r2"
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Package rabbitmq-messaging-topology-operator version 1.16.0-r2 fixes 1 vulnerabilities: ghsa-259r-337f-4rfw",
      "id": "CLEANSTART-2026-BB29139",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-08-13T12:10:09Z",
      "references": [
        {
          "type": "WEB",
          "url": "https://github.com/rabbitmq/messaging-topology-operator"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "summary": "Security fixes in rabbitmq-messaging-topology-operator 1.16.0-r2",
      "upstream": [
        "ghsa-259r-337f-4rfw"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-BE07554 (CVE-2026-2303)

    Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    Security fixes in karma 0.129-r1
    Details

    Package karma version 0.129-r1 fixes 6 vulnerabilities: CVE-2026-2303, CVE-2026-39824, ghsa-259r-337f-4rfw, ghsa-3fxj-6jh8-hvhx, ghsa-9g5q-2w5x-hmxf...

    References

    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "karma"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "0.129-r1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "0.129-r1"
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Package karma version 0.129-r1 fixes 6 vulnerabilities: CVE-2026-2303, CVE-2026-39824, ghsa-259r-337f-4rfw, ghsa-3fxj-6jh8-hvhx, ghsa-9g5q-2w5x-hmxf...",
      "id": "CLEANSTART-2026-BE07554",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-09-01T11:17:16Z",
      "references": [
        {
          "type": "WEB",
          "url": "https://github.com/prymitive/karma.git"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "summary": "Security fixes in karma 0.129-r1",
      "upstream": [
        "CVE-2026-2303",
        "CVE-2026-39824",
        "ghsa-259r-337f-4rfw",
        "ghsa-3fxj-6jh8-hvhx",
        "ghsa-9g5q-2w5x-hmxf",
        "ghsa-rjr7-jggh-pgcp"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-BE94448 (GHSA-259R-337F-4RFW)

    Vulnerability from cleanstart – Published: 2026-08-13 12:10 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    Security fixes in nats-streaming 0.23.2-r1
    Details

    Package nats-streaming version 0.23.2-r1 fixes 1 vulnerabilities: ghsa-259r-337f-4rfw


    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "nats-streaming"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "0.23.2-r1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "0.23.2-r1"
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Package nats-streaming version 0.23.2-r1 fixes 1 vulnerabilities: ghsa-259r-337f-4rfw",
      "id": "CLEANSTART-2026-BE94448",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-08-13T12:10:09Z",
      "references": [
        {
          "type": "WEB",
          "url": "https://github.com/nats-io/nats-streaming-server"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "summary": "Security fixes in nats-streaming 0.23.2-r1",
      "upstream": [
        "ghsa-259r-337f-4rfw"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-BR58082 (CVE-2023-42821)

    Vulnerability from cleanstart – Published: 2026-09-10 02:53 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    Echo is a Go web framework
    Details

    Multiple security vulnerabilities affect the kube-metrics-adapter package. Echo is a Go web framework. See references for individual vulnerability details.

    References
    https://github.com/cleanstart-dev/cleanstart-secu… ADVISORY
    https://osv.dev/vulnerability/CVE-2023-42821 WEB
    https://osv.dev/vulnerability/CVE-2026-33818 WEB
    https://osv.dev/vulnerability/CVE-2026-39821 WEB
    https://osv.dev/vulnerability/CVE-2026-40890 WEB
    https://osv.dev/vulnerability/CVE-2026-40898 WEB
    https://osv.dev/vulnerability/CVE-2026-41178 WEB
    https://osv.dev/vulnerability/CVE-2026-46600 WEB
    https://osv.dev/vulnerability/CVE-2026-55677 WEB
    https://osv.dev/vulnerability/CVE-2026-56853 WEB
    https://osv.dev/vulnerability/CVE-2026-56858 WEB
    https://osv.dev/vulnerability/CVE-2026-56859 WEB
    https://osv.dev/vulnerability/CVE-2026-56860 WEB
    https://osv.dev/vulnerability/CVE-2026-56862 WEB
    https://osv.dev/vulnerability/CVE-2026-73500 WEB
    https://osv.dev/vulnerability/ghsa-259r-337f-4rfw WEB
    https://osv.dev/vulnerability/ghsa-gcjh-h69q-9w9g WEB
    https://osv.dev/vulnerability/ghsa-hrxh-6v49-42gf WEB
    https://nvd.nist.gov/vuln/detail/CVE-2023-42821 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-33818 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39821 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-40890 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-40898 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-41178 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-46600 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-55677 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56853 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56858 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56859 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56860 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56862 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-73500 WEB

    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "kube-metrics-adapter"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "0.2.9-r2"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Multiple security vulnerabilities affect the kube-metrics-adapter package. Echo is a Go web framework. See references for individual vulnerability details.",
      "id": "CLEANSTART-2026-BR58082",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-09-10T02:53:42.246802Z",
      "references": [
        {
          "type": "ADVISORY",
          "url": "https://github.com/cleanstart-dev/cleanstart-security-advisories/tree/main/advisories/2026/CLEANSTART-2026-BR58082.json"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2023-42821"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-33818"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39821"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-40890"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-40898"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-41178"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-46600"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-55677"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56853"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56858"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56859"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56860"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56862"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-73500"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-259r-337f-4rfw"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-gcjh-h69q-9w9g"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-hrxh-6v49-42gf"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-42821"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33818"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39821"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-40890"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-40898"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41178"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46600"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-55677"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56853"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56858"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56859"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56860"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56862"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-73500"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "severity": [
        {
          "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "type": "CVSS_V3"
        }
      ],
      "summary": "Echo is a Go web framework",
      "upstream": [
        "CVE-2023-42821",
        "CVE-2026-33818",
        "CVE-2026-39821",
        "CVE-2026-40890",
        "CVE-2026-40898",
        "CVE-2026-41178",
        "CVE-2026-46600",
        "CVE-2026-55677",
        "CVE-2026-56853",
        "CVE-2026-56858",
        "CVE-2026-56859",
        "CVE-2026-56860",
        "CVE-2026-56862",
        "CVE-2026-73500",
        "ghsa-259r-337f-4rfw",
        "ghsa-gcjh-h69q-9w9g",
        "ghsa-hrxh-6v49-42gf"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-BT15862 (GHSA-259R-337F-4RFW)

    Vulnerability from cleanstart – Published: 2026-08-13 12:10 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    Security fixes in ollama-fips 0.30.11-r2
    Details

    Package ollama-fips version 0.30.11-r2 fixes 1 vulnerabilities: ghsa-259r-337f-4rfw

    References

    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "ollama-fips"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "0.30.11-r2"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "0.30.11-r2"
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Package ollama-fips version 0.30.11-r2 fixes 1 vulnerabilities: ghsa-259r-337f-4rfw",
      "id": "CLEANSTART-2026-BT15862",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-08-13T12:10:09Z",
      "references": [
        {
          "type": "WEB",
          "url": "https://ollama.com"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "summary": "Security fixes in ollama-fips 0.30.11-r2",
      "upstream": [
        "ghsa-259r-337f-4rfw"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-BY91066 (CVE-2025-15558)

    Vulnerability from cleanstart – Published: 2026-09-08 02:00 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    malicious GOSUMDB was capable of serving arbitrary module content not contained within the transparency log
    Details

    Multiple security vulnerabilities affect the dynatrace-operator package. A malicious GOSUMDB was capable of serving arbitrary module content not contained within the transparency log. See references for individual vulnerability details.


    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "dynatrace-operator"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "1.8.1-r5"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Multiple security vulnerabilities affect the dynatrace-operator package. A malicious GOSUMDB was capable of serving arbitrary module content not contained within the transparency log. See references for individual vulnerability details.",
      "id": "CLEANSTART-2026-BY91066",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-09-08T02:00:36.015974Z",
      "references": [
        {
          "type": "ADVISORY",
          "url": "https://github.com/cleanstart-dev/cleanstart-security-advisories/tree/main/advisories/2026/CLEANSTART-2026-BY91066.json"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-15558"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-33818"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39821"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39822"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-41178"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42504"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42505"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-46600"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56852"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56859"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56864"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-259r-337f-4rfw"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-15558"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33818"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39821"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39822"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41178"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42504"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42505"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46600"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56852"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56859"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56864"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "severity": [
        {
          "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "type": "CVSS_V3"
        }
      ],
      "summary": "malicious GOSUMDB was capable of serving arbitrary module content not contained within the transparency log",
      "upstream": [
        "CVE-2025-15558",
        "CVE-2026-33818",
        "CVE-2026-39821",
        "CVE-2026-39822",
        "CVE-2026-41178",
        "CVE-2026-42504",
        "CVE-2026-42505",
        "CVE-2026-46600",
        "CVE-2026-56852",
        "CVE-2026-56859",
        "CVE-2026-56864",
        "ghsa-259r-337f-4rfw"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-CD03295 (CVE-2026-53492)

    Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    Security fixes in rancher-agent 2.11.15-r1
    Details

    Package rancher-agent version 2.11.15-r1 fixes 28 vulnerabilities: CVE-2026-53492, CVE-2026-50195, CVE-2026-53489, CVE-2024-40635, CVE-2024-25621...

    References

    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "rancher-agent"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "2.11.15-r1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "2.11.15-r1"
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Package rancher-agent version 2.11.15-r1 fixes 28 vulnerabilities: CVE-2026-53492, CVE-2026-50195, CVE-2026-53489, CVE-2024-40635, CVE-2024-25621...",
      "id": "CLEANSTART-2026-CD03295",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-09-01T11:17:16Z",
      "references": [
        {
          "type": "WEB",
          "url": "https://github.com/rancher/rancher"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "summary": "Security fixes in rancher-agent 2.11.15-r1",
      "upstream": [
        "CVE-2026-53492",
        "CVE-2026-50195",
        "CVE-2026-53489",
        "CVE-2024-40635",
        "CVE-2024-25621",
        "CVE-2025-64329",
        "CVE-2024-41110",
        "CVE-2026-33997",
        "CVE-2026-41567",
        "CVE-2026-42306",
        "CVE-2026-41568",
        "CVE-2025-15558",
        "CVE-2024-29018",
        "CVE-2024-24557",
        "CVE-2026-34040",
        "CVE-2025-54410",
        "ghsa-hrxh-6v49-42gf",
        "CVE-2026-56864",
        "CVE-2026-56865",
        "CVE-2026-56852",
        "CVE-2026-48978",
        "CVE-2026-50151",
        "CVE-2026-50163",
        "CVE-2026-50162",
        "ghsa-vh4v-2xq2-g5cg",
        "ghsa-gcjh-h69q-9w9g",
        "CVE-2026-41178",
        "ghsa-259r-337f-4rfw"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-CN27602 (CVE-2025-15558)

    Vulnerability from cleanstart – Published: 2026-09-15 01:05 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection
    Details

    Multiple security vulnerabilities affect the minio-operator package. Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. See references for individual vulnerability details.

    References
    https://github.com/cleanstart-dev/cleanstart-secu… ADVISORY
    https://osv.dev/vulnerability/CVE-2025-15558 WEB
    https://osv.dev/vulnerability/CVE-2025-22868 WEB
    https://osv.dev/vulnerability/CVE-2025-30204 WEB
    https://osv.dev/vulnerability/CVE-2025-47912 WEB
    https://osv.dev/vulnerability/CVE-2025-58183 WEB
    https://osv.dev/vulnerability/CVE-2025-58185 WEB
    https://osv.dev/vulnerability/CVE-2025-58186 WEB
    https://osv.dev/vulnerability/CVE-2025-58187 WEB
    https://osv.dev/vulnerability/CVE-2025-58188 WEB
    https://osv.dev/vulnerability/CVE-2025-58189 WEB
    https://osv.dev/vulnerability/CVE-2025-61723 WEB
    https://osv.dev/vulnerability/CVE-2025-61724 WEB
    https://osv.dev/vulnerability/CVE-2025-61725 WEB
    https://osv.dev/vulnerability/CVE-2025-61726 WEB
    https://osv.dev/vulnerability/CVE-2025-61727 WEB
    https://osv.dev/vulnerability/CVE-2025-61728 WEB
    https://osv.dev/vulnerability/CVE-2025-61729 WEB
    https://osv.dev/vulnerability/CVE-2025-61730 WEB
    https://osv.dev/vulnerability/CVE-2025-61731 WEB
    https://osv.dev/vulnerability/CVE-2025-61732 WEB
    https://osv.dev/vulnerability/CVE-2025-68119 WEB
    https://osv.dev/vulnerability/CVE-2025-68121 WEB
    https://osv.dev/vulnerability/CVE-2026-25679 WEB
    https://osv.dev/vulnerability/CVE-2026-25680 WEB
    https://osv.dev/vulnerability/CVE-2026-27139 WEB
    https://osv.dev/vulnerability/CVE-2026-27142 WEB
    https://osv.dev/vulnerability/CVE-2026-27145 WEB
    https://osv.dev/vulnerability/CVE-2026-33814 WEB
    https://osv.dev/vulnerability/CVE-2026-33818 WEB
    https://osv.dev/vulnerability/CVE-2026-39821 WEB
    https://osv.dev/vulnerability/CVE-2026-39822 WEB
    https://osv.dev/vulnerability/CVE-2026-39833 WEB
    https://osv.dev/vulnerability/CVE-2026-39836 WEB
    https://osv.dev/vulnerability/CVE-2026-42499 WEB
    https://osv.dev/vulnerability/CVE-2026-42504 WEB
    https://osv.dev/vulnerability/CVE-2026-42505 WEB
    https://osv.dev/vulnerability/CVE-2026-42507 WEB
    https://osv.dev/vulnerability/CVE-2026-42508 WEB
    https://osv.dev/vulnerability/CVE-2026-46595 WEB
    https://osv.dev/vulnerability/CVE-2026-46600 WEB
    https://osv.dev/vulnerability/CVE-2026-56852 WEB
    https://osv.dev/vulnerability/CVE-2026-56853 WEB
    https://osv.dev/vulnerability/CVE-2026-56855 WEB
    https://osv.dev/vulnerability/CVE-2026-56858 WEB
    https://osv.dev/vulnerability/CVE-2026-56859 WEB
    https://osv.dev/vulnerability/CVE-2026-56860 WEB
    https://osv.dev/vulnerability/CVE-2026-56862 WEB
    https://osv.dev/vulnerability/CVE-2026-56864 WEB
    https://osv.dev/vulnerability/CVE-2026-56865 WEB
    https://osv.dev/vulnerability/CVE-2026-78662 WEB
    https://osv.dev/vulnerability/ghsa-259r-337f-4rfw WEB
    https://osv.dev/vulnerability/ghsa-6v2p-p543-phr9 WEB
    https://osv.dev/vulnerability/ghsa-f6x5-jh6r-wrfv WEB
    https://osv.dev/vulnerability/ghsa-j5w8-q4qc-rx2x WEB
    https://osv.dev/vulnerability/ghsa-p436-gjf2-799p WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-15558 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-22868 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-30204 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-47912 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-58183 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-58185 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-58186 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-58187 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-58188 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-58189 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-61723 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-61724 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-61725 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-61726 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-61727 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-61728 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-61729 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-61730 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-61731 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-61732 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-68119 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-68121 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-25679 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-25680 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-27139 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-27142 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-27145 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-33814 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-33818 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39821 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39822 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39833 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39836 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42499 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42504 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42505 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42507 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42508 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-46595 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-46600 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56852 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56853 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56855 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56858 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56859 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56860 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56862 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56864 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56865 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-78662 WEB

    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "minio-operator"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "7.1.1-r5"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Multiple security vulnerabilities affect the minio-operator package. Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. See references for individual vulnerability details.",
      "id": "CLEANSTART-2026-CN27602",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-09-15T01:05:42.370597Z",
      "references": [
        {
          "type": "ADVISORY",
          "url": "https://github.com/cleanstart-dev/cleanstart-security-advisories/tree/main/advisories/2026/CLEANSTART-2026-CN27602.json"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-15558"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-22868"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-30204"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-47912"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-58183"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-58185"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-58186"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-58187"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-58188"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-58189"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-61723"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-61724"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-61725"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-61726"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-61727"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-61728"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-61729"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-61730"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-61731"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-61732"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-68119"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-68121"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-25679"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-25680"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-27139"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-27142"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-27145"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-33814"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-33818"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39821"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39822"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39833"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39836"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42499"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42504"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42505"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42507"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42508"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-46595"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-46600"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56852"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56853"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56855"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56858"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56859"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56860"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56862"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56864"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56865"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-78662"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-259r-337f-4rfw"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-6v2p-p543-phr9"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-f6x5-jh6r-wrfv"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-j5w8-q4qc-rx2x"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-p436-gjf2-799p"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-15558"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22868"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30204"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47912"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58183"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58185"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58186"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58187"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58188"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58189"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61723"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61724"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61725"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61726"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61727"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61728"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61729"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61730"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61731"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61732"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-68119"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-68121"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25679"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25680"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27139"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27142"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27145"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33814"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33818"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39821"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39822"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39833"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39836"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42499"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42504"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42505"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42507"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42508"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46595"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46600"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56852"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56853"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56855"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56858"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56859"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56860"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56862"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56864"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56865"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78662"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "severity": [
        {
          "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "type": "CVSS_V3"
        }
      ],
      "summary": "Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection",
      "upstream": [
        "CVE-2025-15558",
        "CVE-2025-22868",
        "CVE-2025-30204",
        "CVE-2025-47912",
        "CVE-2025-58183",
        "CVE-2025-58185",
        "CVE-2025-58186",
        "CVE-2025-58187",
        "CVE-2025-58188",
        "CVE-2025-58189",
        "CVE-2025-61723",
        "CVE-2025-61724",
        "CVE-2025-61725",
        "CVE-2025-61726",
        "CVE-2025-61727",
        "CVE-2025-61728",
        "CVE-2025-61729",
        "CVE-2025-61730",
        "CVE-2025-61731",
        "CVE-2025-61732",
        "CVE-2025-68119",
        "CVE-2025-68121",
        "CVE-2026-25679",
        "CVE-2026-25680",
        "CVE-2026-27139",
        "CVE-2026-27142",
        "CVE-2026-27145",
        "CVE-2026-33814",
        "CVE-2026-33818",
        "CVE-2026-39821",
        "CVE-2026-39822",
        "CVE-2026-39833",
        "CVE-2026-39836",
        "CVE-2026-42499",
        "CVE-2026-42504",
        "CVE-2026-42505",
        "CVE-2026-42507",
        "CVE-2026-42508",
        "CVE-2026-46595",
        "CVE-2026-46600",
        "CVE-2026-56852",
        "CVE-2026-56853",
        "CVE-2026-56855",
        "CVE-2026-56858",
        "CVE-2026-56859",
        "CVE-2026-56860",
        "CVE-2026-56862",
        "CVE-2026-56864",
        "CVE-2026-56865",
        "CVE-2026-78662",
        "ghsa-259r-337f-4rfw",
        "ghsa-6v2p-p543-phr9",
        "ghsa-f6x5-jh6r-wrfv",
        "ghsa-j5w8-q4qc-rx2x",
        "ghsa-p436-gjf2-799p"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-CP63847 (CVE-2026-39821)

    Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    Security fixes in temporal-server 1.28.4-r1
    Details

    Package temporal-server version 1.28.4-r1 fixes 15 vulnerabilities: CVE-2026-39821, CVE-2026-33818, CVE-2026-46600, CVE-2026-56853, CVE-2026-56858...

    References

    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "temporal-server"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "1.28.4-r1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "1.28.4-r1"
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Package temporal-server version 1.28.4-r1 fixes 15 vulnerabilities: CVE-2026-39821, CVE-2026-33818, CVE-2026-46600, CVE-2026-56853, CVE-2026-56858...",
      "id": "CLEANSTART-2026-CP63847",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-09-01T11:17:16Z",
      "references": [
        {
          "type": "WEB",
          "url": "https://github.com/temporalio/temporal"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "summary": "Security fixes in temporal-server 1.28.4-r1",
      "upstream": [
        "CVE-2026-39821",
        "CVE-2026-33818",
        "CVE-2026-46600",
        "CVE-2026-56853",
        "CVE-2026-56858",
        "CVE-2026-56859",
        "CVE-2026-56860",
        "CVE-2026-56862",
        "CVE-2026-5724",
        "CVE-2025-14987",
        "CVE-2025-14986",
        "CVE-2026-5199",
        "ghsa-hrxh-6v49-42gf",
        "ghsa-259r-337f-4rfw",
        "CVE-2026-41178"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-CY42435 (CVE-2026-42508)

    Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    Security fixes in amazon-cloudwatch-agent 1.300071.0-r1
    Details

    Package amazon-cloudwatch-agent version 1.300071.0-r1 fixes 36 vulnerabilities: CVE-2026-42508, CVE-2026-39835, CVE-2026-46598, CVE-2026-39828, CVE-2026-39829...


    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "amazon-cloudwatch-agent"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "1.300071.0-r1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "1.300071.0-r1"
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Package amazon-cloudwatch-agent version 1.300071.0-r1 fixes 36 vulnerabilities: CVE-2026-42508, CVE-2026-39835, CVE-2026-46598, CVE-2026-39828, CVE-2026-39829...",
      "id": "CLEANSTART-2026-CY42435",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-09-01T11:17:16Z",
      "references": [
        {
          "type": "WEB",
          "url": "https://github.com/aws/amazon-cloudwatch-agent"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "summary": "Security fixes in amazon-cloudwatch-agent 1.300071.0-r1",
      "upstream": [
        "CVE-2026-42508",
        "CVE-2026-39835",
        "CVE-2026-46598",
        "CVE-2026-39828",
        "CVE-2026-39829",
        "CVE-2026-46597",
        "CVE-2026-39830",
        "CVE-2026-39831",
        "CVE-2026-39832",
        "CVE-2026-39833",
        "CVE-2026-39834",
        "CVE-2026-46595",
        "CVE-2026-39827",
        "CVE-2026-33997",
        "CVE-2026-41567",
        "CVE-2026-42306",
        "CVE-2026-34040",
        "CVE-2026-41568",
        "ghsa-hrxh-6v49-42gf",
        "CVE-2026-46600",
        "CVE-2026-25681",
        "CVE-2026-27136",
        "CVE-2026-39821",
        "CVE-2026-42502",
        "CVE-2026-42506",
        "CVE-2026-25680",
        "CVE-2026-42151",
        "CVE-2026-44903",
        "CVE-2026-40179",
        "CVE-2026-56852",
        "CVE-2026-39824",
        "ghsa-xmrv-pmrh-hhx2",
        "CVE-2026-2303",
        "CVE-2026-41178",
        "CVE-2026-42154",
        "ghsa-259r-337f-4rfw"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-EC97009 (GHSA-HRXH-6V49-42GF)

    Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    Security fixes in argo-cd 3.4.5-r2
    Details

    Package argo-cd version 3.4.5-r2 fixes 3 vulnerabilities: ghsa-hrxh-6v49-42gf, ghsa-259r-337f-4rfw, CVE-2026-41178

    References

    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "argo-cd"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "3.4.5-r2"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "3.4.5-r2"
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Package argo-cd version 3.4.5-r2 fixes 3 vulnerabilities: ghsa-hrxh-6v49-42gf, ghsa-259r-337f-4rfw, CVE-2026-41178",
      "id": "CLEANSTART-2026-EC97009",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-09-01T11:17:16Z",
      "references": [
        {
          "type": "WEB",
          "url": "https://github.com/argoproj/argo-cd"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "summary": "Security fixes in argo-cd 3.4.5-r2",
      "upstream": [
        "ghsa-hrxh-6v49-42gf",
        "ghsa-259r-337f-4rfw",
        "CVE-2026-41178"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-EK79845 (GHSA-259R-337F-4RFW)

    Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    Security fixes in ollama 0.32.9-r1
    Details

    Package ollama version 0.32.9-r1 fixes 1 vulnerabilities: ghsa-259r-337f-4rfw

    References

    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "ollama"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "0.32.9-r1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "0.32.9-r1"
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Package ollama version 0.32.9-r1 fixes 1 vulnerabilities: ghsa-259r-337f-4rfw",
      "id": "CLEANSTART-2026-EK79845",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-09-01T11:17:16Z",
      "references": [
        {
          "type": "WEB",
          "url": "https://ollama.com"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "summary": "Security fixes in ollama 0.32.9-r1",
      "upstream": [
        "ghsa-259r-337f-4rfw"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-EM47790 (CVE-2025-15558)

    Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    Security fixes in tkn 0.42.2-r1
    Details

    Package tkn version 0.42.2-r1 fixes 57 vulnerabilities: CVE-2025-15558, CVE-2026-34040, CVE-2026-33997, CVE-2025-69725, CVE-2026-34986...

    References

    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "tkn"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "0.42.2-r1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "0.42.2-r1"
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Package tkn version 0.42.2-r1 fixes 57 vulnerabilities: CVE-2025-15558, CVE-2026-34040, CVE-2026-33997, CVE-2025-69725, CVE-2026-34986...",
      "id": "CLEANSTART-2026-EM47790",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-09-01T11:17:16Z",
      "references": [
        {
          "type": "WEB",
          "url": "https://github.com/tektoncd/cli"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "summary": "Security fixes in tkn 0.42.2-r1",
      "upstream": [
        "CVE-2025-15558",
        "CVE-2026-34040",
        "CVE-2026-33997",
        "CVE-2025-69725",
        "CVE-2026-34986",
        "ghsa-gcjh-h69q-9w9g",
        "CVE-2025-62375",
        "ghsa-pmwq-pjrm-6p5r",
        "CVE-2026-49478",
        "CVE-2026-22772",
        "CVE-2026-48702",
        "CVE-2026-23831",
        "CVE-2026-24117",
        "CVE-2026-54787",
        "CVE-2026-49834",
        "CVE-2026-49835",
        "CVE-2026-39984",
        "CVE-2026-2303",
        "CVE-2026-29181",
        "CVE-2026-39883",
        "CVE-2026-24051",
        "CVE-2026-39828",
        "CVE-2026-39829",
        "CVE-2026-39830",
        "CVE-2026-39831",
        "CVE-2026-39832",
        "CVE-2026-39835",
        "CVE-2026-42508",
        "CVE-2026-46595",
        "CVE-2026-46597",
        "CVE-2026-39827",
        "CVE-2026-39833",
        "CVE-2026-39834",
        "CVE-2026-33818",
        "CVE-2026-56853",
        "CVE-2026-56858",
        "CVE-2026-56859",
        "CVE-2026-56860",
        "CVE-2026-56862",
        "CVE-2026-46598",
        "CVE-2026-46600",
        "CVE-2026-25681",
        "CVE-2026-27136",
        "CVE-2026-39821",
        "CVE-2026-25680",
        "CVE-2026-42502",
        "CVE-2026-42506",
        "CVE-2026-33814",
        "CVE-2026-39824",
        "CVE-2026-56852",
        "ghsa-hrxh-6v49-42gf",
        "CVE-2026-56864",
        "CVE-2026-56865",
        "ghsa-259r-337f-4rfw",
        "ghsa-3fxj-6jh8-hvhx",
        "ghsa-9g5q-2w5x-hmxf",
        "ghsa-rjr7-jggh-pgcp"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-EP36304 (GHSA-259R-337F-4RFW)

    Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    Security fixes in ollama-fips 0.32.1-r1
    Details

    Package ollama-fips version 0.32.1-r1 fixes 1 vulnerabilities: ghsa-259r-337f-4rfw

    References

    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "ollama-fips"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "0.32.1-r1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "0.32.1-r1"
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Package ollama-fips version 0.32.1-r1 fixes 1 vulnerabilities: ghsa-259r-337f-4rfw",
      "id": "CLEANSTART-2026-EP36304",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-09-01T11:17:16Z",
      "references": [
        {
          "type": "WEB",
          "url": "https://ollama.com"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "summary": "Security fixes in ollama-fips 0.32.1-r1",
      "upstream": [
        "ghsa-259r-337f-4rfw"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-ER95870 (GHSA-259R-337F-4RFW)

    Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    Security fixes in tempo 2.9.5-r2
    Details

    Package tempo version 2.9.5-r2 fixes 1 vulnerabilities: ghsa-259r-337f-4rfw

    References

    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "tempo"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "2.9.5-r2"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "2.9.5-r2"
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Package tempo version 2.9.5-r2 fixes 1 vulnerabilities: ghsa-259r-337f-4rfw",
      "id": "CLEANSTART-2026-ER95870",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-09-01T11:17:16Z",
      "references": [
        {
          "type": "WEB",
          "url": "https://github.com/grafana/tempo"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "summary": "Security fixes in tempo 2.9.5-r2",
      "upstream": [
        "ghsa-259r-337f-4rfw"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-ET14314 (GHSA-259R-337F-4RFW)

    Vulnerability from cleanstart – Published: 2026-08-13 12:10 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    Security fixes in cortex 1.19.1-r2
    Details

    Package cortex version 1.19.1-r2 fixes 2 vulnerabilities: ghsa-259r-337f-4rfw, CVE-2026-41178

    References

    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "cortex"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "1.19.1-r2"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "1.19.1-r2"
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Package cortex version 1.19.1-r2 fixes 2 vulnerabilities: ghsa-259r-337f-4rfw, CVE-2026-41178",
      "id": "CLEANSTART-2026-ET14314",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-08-13T12:10:09Z",
      "references": [
        {
          "type": "WEB",
          "url": "https://github.com/cortexproject/cortex"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "summary": "Security fixes in cortex 1.19.1-r2",
      "upstream": [
        "ghsa-259r-337f-4rfw",
        "CVE-2026-41178"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-FD87409 (CVE-2026-33818)

    Vulnerability from cleanstart – Published: 2026-09-10 03:04 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI

    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "nats-streaming"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "0.24.6-r5"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Multiple security vulnerabilities affect the nats-streaming package. Previously, resolving relative paths containing parent directory (\u0027. See references for individual vulnerability details.",
      "id": "CLEANSTART-2026-FD87409",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-09-10T03:04:43.115167Z",
      "references": [
        {
          "type": "ADVISORY",
          "url": "https://github.com/cleanstart-dev/cleanstart-security-advisories/tree/main/advisories/2026/CLEANSTART-2026-FD87409.json"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-33818"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39822"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42504"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42505"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-46600"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56853"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56858"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56860"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-259r-337f-4rfw"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33818"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39822"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42504"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42505"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46600"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56853"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56858"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56860"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "severity": [
        {
          "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "type": "CVSS_V3"
        }
      ],
      "summary": "Previously, resolving relative paths containing parent directory (\u0027",
      "upstream": [
        "CVE-2026-33818",
        "CVE-2026-39822",
        "CVE-2026-42504",
        "CVE-2026-42505",
        "CVE-2026-46600",
        "CVE-2026-56853",
        "CVE-2026-56858",
        "CVE-2026-56860",
        "ghsa-259r-337f-4rfw"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-FI83495 (GHSA-259R-337F-4RFW)

    Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    Security fixes in ollama 0.32.0-r1
    Details

    Package ollama version 0.32.0-r1 fixes 1 vulnerabilities: ghsa-259r-337f-4rfw

    References

    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "ollama"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "0.32.0-r1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "0.32.0-r1"
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Package ollama version 0.32.0-r1 fixes 1 vulnerabilities: ghsa-259r-337f-4rfw",
      "id": "CLEANSTART-2026-FI83495",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-09-01T11:17:16Z",
      "references": [
        {
          "type": "WEB",
          "url": "https://ollama.com"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "summary": "Security fixes in ollama 0.32.0-r1",
      "upstream": [
        "ghsa-259r-337f-4rfw"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-FL45169 (GHSA-259R-337F-4RFW)

    Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    Security fixes in ollama-fips 0.32.14-r2
    Details

    Package ollama-fips version 0.32.14-r2 fixes 1 vulnerabilities: ghsa-259r-337f-4rfw

    References

    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "ollama-fips"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "0.32.14-r2"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "0.32.14-r2"
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Package ollama-fips version 0.32.14-r2 fixes 1 vulnerabilities: ghsa-259r-337f-4rfw",
      "id": "CLEANSTART-2026-FL45169",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-09-01T11:17:16Z",
      "references": [
        {
          "type": "WEB",
          "url": "https://ollama.com"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "summary": "Security fixes in ollama-fips 0.32.14-r2",
      "upstream": [
        "ghsa-259r-337f-4rfw"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-FT20664 (CVE-2025-47912)

    Vulnerability from cleanstart – Published: 2026-09-08 02:12 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    gRPC-Go is the Go language implementation of gRPC
    Details

    Multiple security vulnerabilities affect the step package. gRPC-Go is the Go language implementation of gRPC. See references for individual vulnerability details.

    References
    https://github.com/cleanstart-dev/cleanstart-secu… ADVISORY
    https://osv.dev/vulnerability/CVE-2025-47912 WEB
    https://osv.dev/vulnerability/CVE-2025-58183 WEB
    https://osv.dev/vulnerability/CVE-2025-58185 WEB
    https://osv.dev/vulnerability/CVE-2025-58186 WEB
    https://osv.dev/vulnerability/CVE-2025-58187 WEB
    https://osv.dev/vulnerability/CVE-2025-58188 WEB
    https://osv.dev/vulnerability/CVE-2025-58189 WEB
    https://osv.dev/vulnerability/CVE-2025-61723 WEB
    https://osv.dev/vulnerability/CVE-2025-61724 WEB
    https://osv.dev/vulnerability/CVE-2025-61725 WEB
    https://osv.dev/vulnerability/CVE-2025-62820 WEB
    https://osv.dev/vulnerability/CVE-2025-66406 WEB
    https://osv.dev/vulnerability/CVE-2026-25793 WEB
    https://osv.dev/vulnerability/CVE-2026-30836 WEB
    https://osv.dev/vulnerability/CVE-2026-33818 WEB
    https://osv.dev/vulnerability/CVE-2026-39821 WEB
    https://osv.dev/vulnerability/CVE-2026-39822 WEB
    https://osv.dev/vulnerability/CVE-2026-40097 WEB
    https://osv.dev/vulnerability/CVE-2026-41178 WEB
    https://osv.dev/vulnerability/CVE-2026-42505 WEB
    https://osv.dev/vulnerability/CVE-2026-46600 WEB
    https://osv.dev/vulnerability/CVE-2026-56852 WEB
    https://osv.dev/vulnerability/CVE-2026-56853 WEB
    https://osv.dev/vulnerability/CVE-2026-56855 WEB
    https://osv.dev/vulnerability/CVE-2026-56858 WEB
    https://osv.dev/vulnerability/CVE-2026-56859 WEB
    https://osv.dev/vulnerability/CVE-2026-56860 WEB
    https://osv.dev/vulnerability/CVE-2026-56862 WEB
    https://osv.dev/vulnerability/CVE-2026-78662 WEB
    https://osv.dev/vulnerability/CVE-2026-84304 WEB
    https://osv.dev/vulnerability/ghsa-259r-337f-4rfw WEB
    https://osv.dev/vulnerability/ghsa-3fxj-6jh8-hvhx WEB
    https://osv.dev/vulnerability/ghsa-9g5q-2w5x-hmxf WEB
    https://osv.dev/vulnerability/ghsa-hrxh-6v49-42gf WEB
    https://osv.dev/vulnerability/ghsa-rjr7-jggh-pgcp WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-47912 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-58183 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-58185 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-58186 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-58187 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-58188 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-58189 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-61723 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-61724 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-61725 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-62820 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-66406 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-25793 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-30836 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-33818 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39821 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39822 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-40097 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-41178 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42505 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-46600 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56852 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56853 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56855 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56858 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56859 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56860 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56862 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-78662 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-84304 WEB

    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "step"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "0.28.7-r6"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Multiple security vulnerabilities affect the step package. gRPC-Go is the Go language implementation of gRPC. See references for individual vulnerability details.",
      "id": "CLEANSTART-2026-FT20664",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-09-08T02:12:53.280158Z",
      "references": [
        {
          "type": "ADVISORY",
          "url": "https://github.com/cleanstart-dev/cleanstart-security-advisories/tree/main/advisories/2026/CLEANSTART-2026-FT20664.json"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-47912"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-58183"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-58185"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-58186"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-58187"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-58188"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-58189"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-61723"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-61724"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-61725"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-62820"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-66406"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-25793"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-30836"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-33818"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39821"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39822"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-40097"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-41178"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42505"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-46600"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56852"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56853"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56855"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56858"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56859"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56860"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56862"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-78662"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-84304"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-259r-337f-4rfw"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-3fxj-6jh8-hvhx"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-9g5q-2w5x-hmxf"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-hrxh-6v49-42gf"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-rjr7-jggh-pgcp"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47912"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58183"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58185"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58186"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58187"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58188"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58189"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61723"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61724"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61725"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-62820"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-66406"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25793"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-30836"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33818"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39821"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39822"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-40097"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41178"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42505"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46600"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56852"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56853"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56855"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56858"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56859"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56860"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56862"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78662"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84304"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "severity": [
        {
          "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "type": "CVSS_V3"
        }
      ],
      "summary": "gRPC-Go is the Go language implementation of gRPC",
      "upstream": [
        "CVE-2025-47912",
        "CVE-2025-58183",
        "CVE-2025-58185",
        "CVE-2025-58186",
        "CVE-2025-58187",
        "CVE-2025-58188",
        "CVE-2025-58189",
        "CVE-2025-61723",
        "CVE-2025-61724",
        "CVE-2025-61725",
        "CVE-2025-62820",
        "CVE-2025-66406",
        "CVE-2026-25793",
        "CVE-2026-30836",
        "CVE-2026-33818",
        "CVE-2026-39821",
        "CVE-2026-39822",
        "CVE-2026-40097",
        "CVE-2026-41178",
        "CVE-2026-42505",
        "CVE-2026-46600",
        "CVE-2026-56852",
        "CVE-2026-56853",
        "CVE-2026-56855",
        "CVE-2026-56858",
        "CVE-2026-56859",
        "CVE-2026-56860",
        "CVE-2026-56862",
        "CVE-2026-78662",
        "CVE-2026-84304",
        "ghsa-259r-337f-4rfw",
        "ghsa-3fxj-6jh8-hvhx",
        "ghsa-9g5q-2w5x-hmxf",
        "ghsa-hrxh-6v49-42gf",
        "ghsa-rjr7-jggh-pgcp"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-FY98026 (GHSA-HRXH-6V49-42GF)

    Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    Security fixes in newrelic-infrastructure-agent 1.76.2-r1
    Details

    Package newrelic-infrastructure-agent version 1.76.2-r1 fixes 3 vulnerabilities: ghsa-hrxh-6v49-42gf, CVE-2026-41178, ghsa-259r-337f-4rfw


    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "newrelic-infrastructure-agent"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "1.76.2-r1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "1.76.2-r1"
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Package newrelic-infrastructure-agent version 1.76.2-r1 fixes 3 vulnerabilities: ghsa-hrxh-6v49-42gf, CVE-2026-41178, ghsa-259r-337f-4rfw",
      "id": "CLEANSTART-2026-FY98026",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-09-01T11:17:16Z",
      "references": [
        {
          "type": "WEB",
          "url": "https://github.com/newrelic/infrastructure-agent"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "summary": "Security fixes in newrelic-infrastructure-agent 1.76.2-r1",
      "upstream": [
        "ghsa-hrxh-6v49-42gf",
        "CVE-2026-41178",
        "ghsa-259r-337f-4rfw"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-GB19497 (GHSA-259R-337F-4RFW)

    Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    Security fixes in ollama 0.32.4-r1
    Details

    Package ollama version 0.32.4-r1 fixes 1 vulnerabilities: ghsa-259r-337f-4rfw

    References

    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "ollama"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "0.32.4-r1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "0.32.4-r1"
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Package ollama version 0.32.4-r1 fixes 1 vulnerabilities: ghsa-259r-337f-4rfw",
      "id": "CLEANSTART-2026-GB19497",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-09-01T11:17:16Z",
      "references": [
        {
          "type": "WEB",
          "url": "https://ollama.com"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "summary": "Security fixes in ollama 0.32.4-r1",
      "upstream": [
        "ghsa-259r-337f-4rfw"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-GJ00206 (CVE-2026-39822)

    Vulnerability from cleanstart – Published: 2026-09-17 00:56 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection
    Details

    Multiple security vulnerabilities affect the gitea package. Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. See references for individual vulnerability details.

    References
    https://github.com/cleanstart-dev/cleanstart-secu… ADVISORY
    https://osv.dev/vulnerability/CVE-2026-39822 WEB
    https://osv.dev/vulnerability/CVE-2026-42505 WEB
    https://osv.dev/vulnerability/CVE-2026-46603 WEB
    https://osv.dev/vulnerability/CVE-2026-56855 WEB
    https://osv.dev/vulnerability/CVE-2026-56864 WEB
    https://osv.dev/vulnerability/CVE-2026-56865 WEB
    https://osv.dev/vulnerability/CVE-2026-71556 WEB
    https://osv.dev/vulnerability/CVE-2026-71557 WEB
    https://osv.dev/vulnerability/CVE-2026-78662 WEB
    https://osv.dev/vulnerability/CVE-2026-84303 WEB
    https://osv.dev/vulnerability/CVE-2026-84304 WEB
    https://osv.dev/vulnerability/CVE-2026-84445 WEB
    https://osv.dev/vulnerability/ghsa-259r-337f-4rfw WEB
    https://osv.dev/vulnerability/ghsa-3fxj-6jh8-hvhx WEB
    https://osv.dev/vulnerability/ghsa-9g5q-2w5x-hmxf WEB
    https://osv.dev/vulnerability/ghsa-hrxh-6v49-42gf WEB
    https://osv.dev/vulnerability/ghsa-rjr7-jggh-pgcg WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39822 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42505 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-46603 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56855 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56864 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56865 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-71556 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-71557 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-78662 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-84303 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-84304 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-84445 WEB

    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "gitea"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "1.27.2-r2"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Multiple security vulnerabilities affect the gitea package. Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. See references for individual vulnerability details.",
      "id": "CLEANSTART-2026-GJ00206",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-09-17T00:56:49.342966Z",
      "references": [
        {
          "type": "ADVISORY",
          "url": "https://github.com/cleanstart-dev/cleanstart-security-advisories/tree/main/advisories/2026/CLEANSTART-2026-GJ00206.json"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39822"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42505"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-46603"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56855"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56864"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56865"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-71556"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-71557"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-78662"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-84303"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-84304"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-84445"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-259r-337f-4rfw"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-3fxj-6jh8-hvhx"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-9g5q-2w5x-hmxf"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-hrxh-6v49-42gf"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-rjr7-jggh-pgcg"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39822"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42505"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46603"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56855"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56864"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56865"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-71556"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-71557"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78662"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84303"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84304"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84445"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "severity": [
        {
          "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "type": "CVSS_V3"
        }
      ],
      "summary": "Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection",
      "upstream": [
        "CVE-2026-39822",
        "CVE-2026-42505",
        "CVE-2026-46603",
        "CVE-2026-56855",
        "CVE-2026-56864",
        "CVE-2026-56865",
        "CVE-2026-71556",
        "CVE-2026-71557",
        "CVE-2026-78662",
        "CVE-2026-84303",
        "CVE-2026-84304",
        "CVE-2026-84445",
        "ghsa-259r-337f-4rfw",
        "ghsa-3fxj-6jh8-hvhx",
        "ghsa-9g5q-2w5x-hmxf",
        "ghsa-hrxh-6v49-42gf",
        "ghsa-rjr7-jggh-pgcg"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-GK68352 (CVE-2026-33818)

    Vulnerability from cleanstart – Published: 2026-09-10 01:24 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label
    Details

    Multiple security vulnerabilities affect the kubernetes-dns-node-cache package. The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. See references for individual vulnerability details.

    References
    https://github.com/cleanstart-dev/cleanstart-secu… ADVISORY
    https://osv.dev/vulnerability/CVE-2026-33818 WEB
    https://osv.dev/vulnerability/CVE-2026-39821 WEB
    https://osv.dev/vulnerability/CVE-2026-39822 WEB
    https://osv.dev/vulnerability/CVE-2026-42504 WEB
    https://osv.dev/vulnerability/CVE-2026-42505 WEB
    https://osv.dev/vulnerability/CVE-2026-46600 WEB
    https://osv.dev/vulnerability/CVE-2026-50274 WEB
    https://osv.dev/vulnerability/CVE-2026-56853 WEB
    https://osv.dev/vulnerability/CVE-2026-56858 WEB
    https://osv.dev/vulnerability/CVE-2026-56859 WEB
    https://osv.dev/vulnerability/CVE-2026-56860 WEB
    https://osv.dev/vulnerability/CVE-2026-56862 WEB
    https://osv.dev/vulnerability/CVE-2026-56864 WEB
    https://osv.dev/vulnerability/CVE-2026-56865 WEB
    https://osv.dev/vulnerability/ghsa-259r-337f-4rfw WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-33818 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39821 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39822 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42504 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42505 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-46600 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-50274 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56853 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56858 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56859 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56860 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56862 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56864 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56865 WEB

    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "kubernetes-dns-node-cache"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "1.26.8-r7"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Multiple security vulnerabilities affect the kubernetes-dns-node-cache package. The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. See references for individual vulnerability details.",
      "id": "CLEANSTART-2026-GK68352",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-09-10T01:24:08.392743Z",
      "references": [
        {
          "type": "ADVISORY",
          "url": "https://github.com/cleanstart-dev/cleanstart-security-advisories/tree/main/advisories/2026/CLEANSTART-2026-GK68352.json"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-33818"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39821"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39822"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42504"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42505"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-46600"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-50274"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56853"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56858"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56859"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56860"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56862"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56864"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56865"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-259r-337f-4rfw"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33818"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39821"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39822"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42504"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42505"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46600"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-50274"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56853"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56858"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56859"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56860"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56862"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56864"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56865"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "severity": [
        {
          "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "type": "CVSS_V3"
        }
      ],
      "summary": "ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label",
      "upstream": [
        "CVE-2026-33818",
        "CVE-2026-39821",
        "CVE-2026-39822",
        "CVE-2026-42504",
        "CVE-2026-42505",
        "CVE-2026-46600",
        "CVE-2026-50274",
        "CVE-2026-56853",
        "CVE-2026-56858",
        "CVE-2026-56859",
        "CVE-2026-56860",
        "CVE-2026-56862",
        "CVE-2026-56864",
        "CVE-2026-56865",
        "ghsa-259r-337f-4rfw"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-GO78201 (CVE-2026-33818)

    Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    Security fixes in tkn 0.45.0-r1
    Details

    Package tkn version 0.45.0-r1 fixes 42 vulnerabilities: CVE-2026-33818, CVE-2026-56853, CVE-2026-56858, CVE-2026-56859, CVE-2026-56860...

    References

    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "tkn"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "0.45.0-r1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "0.45.0-r1"
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Package tkn version 0.45.0-r1 fixes 42 vulnerabilities: CVE-2026-33818, CVE-2026-56853, CVE-2026-56858, CVE-2026-56859, CVE-2026-56860...",
      "id": "CLEANSTART-2026-GO78201",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-09-01T11:17:16Z",
      "references": [
        {
          "type": "WEB",
          "url": "https://github.com/tektoncd/cli"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "summary": "Security fixes in tkn 0.45.0-r1",
      "upstream": [
        "CVE-2026-33818",
        "CVE-2026-56853",
        "CVE-2026-56858",
        "CVE-2026-56859",
        "CVE-2026-56860",
        "CVE-2026-56862",
        "CVE-2026-34040",
        "CVE-2026-33997",
        "ghsa-gcjh-h69q-9w9g",
        "CVE-2026-48702",
        "CVE-2026-49834",
        "CVE-2026-54787",
        "CVE-2026-49835",
        "CVE-2026-39828",
        "CVE-2026-39829",
        "CVE-2026-39830",
        "CVE-2026-39831",
        "CVE-2026-39832",
        "CVE-2026-39835",
        "CVE-2026-42508",
        "CVE-2026-46595",
        "CVE-2026-46597",
        "CVE-2026-39827",
        "CVE-2026-39833",
        "CVE-2026-39834",
        "CVE-2026-46598",
        "CVE-2026-25681",
        "CVE-2026-27136",
        "CVE-2026-39821",
        "CVE-2026-46600",
        "CVE-2026-25680",
        "CVE-2026-42502",
        "CVE-2026-42506",
        "CVE-2026-56852",
        "ghsa-hrxh-6v49-42gf",
        "CVE-2026-56864",
        "CVE-2026-56865",
        "ghsa-259r-337f-4rfw",
        "ghsa-3fxj-6jh8-hvhx",
        "ghsa-9g5q-2w5x-hmxf",
        "ghsa-rjr7-jggh-pgcp",
        "CVE-2026-41178"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-GP43617 (GHSA-259R-337F-4RFW)

    Vulnerability from cleanstart – Published: 2026-08-13 12:10 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    Security fixes in argo-workflows 3.7.17-r2
    Details

    Package argo-workflows version 3.7.17-r2 fixes 1 vulnerabilities: ghsa-259r-337f-4rfw


    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "argo-workflows"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "3.7.17-r2"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "3.7.17-r2"
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Package argo-workflows version 3.7.17-r2 fixes 1 vulnerabilities: ghsa-259r-337f-4rfw",
      "id": "CLEANSTART-2026-GP43617",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-08-13T12:10:09Z",
      "references": [
        {
          "type": "WEB",
          "url": "https://github.com/argoproj/argo-workflows"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "summary": "Security fixes in argo-workflows 3.7.17-r2",
      "upstream": [
        "ghsa-259r-337f-4rfw"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-GQ91083 (CVE-2025-61732)

    Vulnerability from cleanstart – Published: 2026-09-08 02:09 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    Previously, a channel registered in the mux's chanList is not usable until it is established
    Details

    Multiple security vulnerabilities affect the victoriametrics-operator-fips package. Previously, a channel registered in the mux's chanList is not usable until it is established. See references for individual vulnerability details.

    References
    https://github.com/cleanstart-dev/cleanstart-secu… ADVISORY
    https://osv.dev/vulnerability/CVE-2025-61732 WEB
    https://osv.dev/vulnerability/CVE-2025-68121 WEB
    https://osv.dev/vulnerability/CVE-2026-25679 WEB
    https://osv.dev/vulnerability/CVE-2026-27139 WEB
    https://osv.dev/vulnerability/CVE-2026-27142 WEB
    https://osv.dev/vulnerability/CVE-2026-33818 WEB
    https://osv.dev/vulnerability/CVE-2026-39821 WEB
    https://osv.dev/vulnerability/CVE-2026-39824 WEB
    https://osv.dev/vulnerability/CVE-2026-41178 WEB
    https://osv.dev/vulnerability/CVE-2026-42504 WEB
    https://osv.dev/vulnerability/CVE-2026-42506 WEB
    https://osv.dev/vulnerability/CVE-2026-42507 WEB
    https://osv.dev/vulnerability/CVE-2026-46600 WEB
    https://osv.dev/vulnerability/CVE-2026-56853 WEB
    https://osv.dev/vulnerability/CVE-2026-56855 WEB
    https://osv.dev/vulnerability/CVE-2026-56858 WEB
    https://osv.dev/vulnerability/CVE-2026-56859 WEB
    https://osv.dev/vulnerability/CVE-2026-56860 WEB
    https://osv.dev/vulnerability/CVE-2026-56862 WEB
    https://osv.dev/vulnerability/CVE-2026-78662 WEB
    https://osv.dev/vulnerability/ghsa-259r-337f-4rfw WEB
    https://osv.dev/vulnerability/ghsa-66jq-2c23-2xh5 WEB
    https://osv.dev/vulnerability/ghsa-9h8m-3fm2-qjrq WEB
    https://osv.dev/vulnerability/ghsa-hrxh-6v49-42gf WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-61732 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-68121 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-25679 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-27139 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-27142 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-33818 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39821 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39824 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-41178 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42504 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42506 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42507 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-46600 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56853 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56855 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56858 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56859 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56860 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56862 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-78662 WEB

    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "victoriametrics-operator-fips"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "0.71.0-r1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Multiple security vulnerabilities affect the victoriametrics-operator-fips package. Previously, a channel registered in the mux\u0027s chanList is not usable until it is established. See references for individual vulnerability details.",
      "id": "CLEANSTART-2026-GQ91083",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-09-08T02:09:21.753541Z",
      "references": [
        {
          "type": "ADVISORY",
          "url": "https://github.com/cleanstart-dev/cleanstart-security-advisories/tree/main/advisories/2026/CLEANSTART-2026-GQ91083.json"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-61732"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-68121"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-25679"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-27139"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-27142"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-33818"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39821"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39824"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-41178"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42504"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42506"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42507"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-46600"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56853"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56855"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56858"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56859"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56860"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56862"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-78662"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-259r-337f-4rfw"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-66jq-2c23-2xh5"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-9h8m-3fm2-qjrq"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-hrxh-6v49-42gf"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61732"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-68121"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25679"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27139"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27142"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33818"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39821"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39824"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41178"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42504"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42506"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42507"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46600"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56853"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56855"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56858"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56859"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56860"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56862"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78662"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "severity": [
        {
          "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "type": "CVSS_V3"
        }
      ],
      "summary": "Previously, a channel registered in the mux\u0027s chanList is not usable until it is established",
      "upstream": [
        "CVE-2025-61732",
        "CVE-2025-68121",
        "CVE-2026-25679",
        "CVE-2026-27139",
        "CVE-2026-27142",
        "CVE-2026-33818",
        "CVE-2026-39821",
        "CVE-2026-39824",
        "CVE-2026-41178",
        "CVE-2026-42504",
        "CVE-2026-42506",
        "CVE-2026-42507",
        "CVE-2026-46600",
        "CVE-2026-56853",
        "CVE-2026-56855",
        "CVE-2026-56858",
        "CVE-2026-56859",
        "CVE-2026-56860",
        "CVE-2026-56862",
        "CVE-2026-78662",
        "ghsa-259r-337f-4rfw",
        "ghsa-66jq-2c23-2xh5",
        "ghsa-9h8m-3fm2-qjrq",
        "ghsa-hrxh-6v49-42gf"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-GR84261 (CVE-2026-33818)

    Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    Security fixes in tekton-chains-fips 0.24.0-r1
    Details

    Package tekton-chains-fips version 0.24.0-r1 fixes 26 vulnerabilities: CVE-2026-33818, CVE-2026-46600, CVE-2026-56853, CVE-2026-56858, CVE-2026-56859...

    References

    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "tekton-chains-fips"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "0.24.0-r1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "0.24.0-r1"
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Package tekton-chains-fips version 0.24.0-r1 fixes 26 vulnerabilities: CVE-2026-33818, CVE-2026-46600, CVE-2026-56853, CVE-2026-56858, CVE-2026-56859...",
      "id": "CLEANSTART-2026-GR84261",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-09-01T11:17:16Z",
      "references": [
        {
          "type": "WEB",
          "url": "https://github.com/tektoncd/chains"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "summary": "Security fixes in tekton-chains-fips 0.24.0-r1",
      "upstream": [
        "CVE-2026-33818",
        "CVE-2026-46600",
        "CVE-2026-56853",
        "CVE-2026-56858",
        "CVE-2026-56859",
        "CVE-2026-56860",
        "CVE-2026-56862",
        "CVE-2026-39821",
        "ghsa-gcjh-h69q-9w9g",
        "ghsa-pmwq-pjrm-6p5r",
        "CVE-2026-22703",
        "CVE-2026-49478",
        "CVE-2026-48702",
        "CVE-2025-66564",
        "CVE-2026-25542",
        "CVE-2026-33022",
        "CVE-2026-2303",
        "CVE-2026-39883",
        "ghsa-hrxh-6v49-42gf",
        "CVE-2026-56864",
        "CVE-2026-56865",
        "ghsa-259r-337f-4rfw",
        "ghsa-3fxj-6jh8-hvhx",
        "ghsa-9g5q-2w5x-hmxf",
        "ghsa-rjr7-jggh-pgcp",
        "CVE-2026-41178"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-GU39170 (CVE-2026-42508)

    Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    Security fixes in amazon-cloudwatch-agent 1.300070.0-r1
    Details

    Package amazon-cloudwatch-agent version 1.300070.0-r1 fixes 37 vulnerabilities: CVE-2026-42508, CVE-2026-39835, CVE-2026-46598, CVE-2026-39828, CVE-2026-39829...


    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "amazon-cloudwatch-agent"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "1.300070.0-r1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "1.300070.0-r1"
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Package amazon-cloudwatch-agent version 1.300070.0-r1 fixes 37 vulnerabilities: CVE-2026-42508, CVE-2026-39835, CVE-2026-46598, CVE-2026-39828, CVE-2026-39829...",
      "id": "CLEANSTART-2026-GU39170",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-09-01T11:17:16Z",
      "references": [
        {
          "type": "WEB",
          "url": "https://github.com/aws/amazon-cloudwatch-agent"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "summary": "Security fixes in amazon-cloudwatch-agent 1.300070.0-r1",
      "upstream": [
        "CVE-2026-42508",
        "CVE-2026-39835",
        "CVE-2026-46598",
        "CVE-2026-39828",
        "CVE-2026-39829",
        "CVE-2026-46597",
        "CVE-2026-39830",
        "CVE-2026-39831",
        "CVE-2026-39832",
        "CVE-2026-39833",
        "CVE-2026-39834",
        "CVE-2026-46595",
        "CVE-2026-39827",
        "CVE-2026-33997",
        "CVE-2026-41567",
        "CVE-2026-42306",
        "CVE-2026-34040",
        "CVE-2026-41568",
        "ghsa-hrxh-6v49-42gf",
        "CVE-2025-63811",
        "CVE-2026-25681",
        "CVE-2026-27136",
        "CVE-2026-39821",
        "CVE-2026-42502",
        "CVE-2026-42506",
        "CVE-2026-25680",
        "CVE-2026-46600",
        "CVE-2026-42151",
        "CVE-2026-44903",
        "CVE-2026-42154",
        "CVE-2026-56852",
        "ghsa-xmrv-pmrh-hhx2",
        "CVE-2026-26958",
        "CVE-2026-2303",
        "CVE-2026-41178",
        "CVE-2026-39824",
        "ghsa-259r-337f-4rfw"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-GV17876 (CVE-2026-25680)

    Vulnerability from cleanstart – Published: 2026-09-08 00:56 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    Helm is a package manager for Charts for Kubernetes
    Details

    Multiple security vulnerabilities affect the rancher-fleet-agent package. Helm is a package manager for Charts for Kubernetes. See references for individual vulnerability details.

    References
    https://github.com/cleanstart-dev/cleanstart-secu… ADVISORY
    https://osv.dev/vulnerability/CVE-2026-25680 WEB
    https://osv.dev/vulnerability/CVE-2026-25681 WEB
    https://osv.dev/vulnerability/CVE-2026-27136 WEB
    https://osv.dev/vulnerability/CVE-2026-29181 WEB
    https://osv.dev/vulnerability/CVE-2026-33186 WEB
    https://osv.dev/vulnerability/CVE-2026-33814 WEB
    https://osv.dev/vulnerability/CVE-2026-35206 WEB
    https://osv.dev/vulnerability/CVE-2026-35469 WEB
    https://osv.dev/vulnerability/CVE-2026-39821 WEB
    https://osv.dev/vulnerability/CVE-2026-39824 WEB
    https://osv.dev/vulnerability/CVE-2026-39827 WEB
    https://osv.dev/vulnerability/CVE-2026-39828 WEB
    https://osv.dev/vulnerability/CVE-2026-39829 WEB
    https://osv.dev/vulnerability/CVE-2026-39830 WEB
    https://osv.dev/vulnerability/CVE-2026-39831 WEB
    https://osv.dev/vulnerability/CVE-2026-39832 WEB
    https://osv.dev/vulnerability/CVE-2026-39833 WEB
    https://osv.dev/vulnerability/CVE-2026-39834 WEB
    https://osv.dev/vulnerability/CVE-2026-39835 WEB
    https://osv.dev/vulnerability/CVE-2026-42502 WEB
    https://osv.dev/vulnerability/CVE-2026-42506 WEB
    https://osv.dev/vulnerability/CVE-2026-42508 WEB
    https://osv.dev/vulnerability/CVE-2026-46595 WEB
    https://osv.dev/vulnerability/CVE-2026-46597 WEB
    https://osv.dev/vulnerability/CVE-2026-46598 WEB
    https://osv.dev/vulnerability/CVE-2026-46600 WEB
    https://osv.dev/vulnerability/CVE-2026-46680 WEB
    https://osv.dev/vulnerability/CVE-2026-47262 WEB
    https://osv.dev/vulnerability/CVE-2026-48978 WEB
    https://osv.dev/vulnerability/CVE-2026-50151 WEB
    https://osv.dev/vulnerability/CVE-2026-50162 WEB
    https://osv.dev/vulnerability/CVE-2026-50163 WEB
    https://osv.dev/vulnerability/CVE-2026-50195 WEB
    https://osv.dev/vulnerability/CVE-2026-53488 WEB
    https://osv.dev/vulnerability/CVE-2026-53489 WEB
    https://osv.dev/vulnerability/CVE-2026-53492 WEB
    https://osv.dev/vulnerability/CVE-2026-56852 WEB
    https://osv.dev/vulnerability/CVE-2026-56854 WEB
    https://osv.dev/vulnerability/CVE-2026-84304 WEB
    https://osv.dev/vulnerability/ghsa-259r-337f-4rfw WEB
    https://osv.dev/vulnerability/ghsa-hrxh-6v49-42gf WEB
    https://osv.dev/vulnerability/ghsa-vh4v-2xq2-g5cg WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-25680 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-25681 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-27136 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-29181 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-33186 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-33814 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-35206 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-35469 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39821 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39824 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39827 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39828 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39829 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39830 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39831 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39832 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39833 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39834 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39835 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42502 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42506 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42508 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-46595 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-46597 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-46598 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-46600 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-46680 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-47262 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-48978 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-50151 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-50162 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-50163 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-50195 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-53488 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-53489 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-53492 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56852 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56854 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-84304 WEB

    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "rancher-fleet-agent"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "0.15.6-r0"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Multiple security vulnerabilities affect the rancher-fleet-agent package. Helm is a package manager for Charts for Kubernetes. See references for individual vulnerability details.",
      "id": "CLEANSTART-2026-GV17876",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-09-08T00:56:47.503504Z",
      "references": [
        {
          "type": "ADVISORY",
          "url": "https://github.com/cleanstart-dev/cleanstart-security-advisories/tree/main/advisories/2026/CLEANSTART-2026-GV17876.json"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-25680"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-25681"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-27136"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-29181"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-33186"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-33814"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-35206"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-35469"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39821"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39824"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39827"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39828"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39829"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39830"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39831"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39832"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39833"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39834"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39835"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42502"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42506"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42508"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-46595"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-46597"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-46598"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-46600"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-46680"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-47262"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-48978"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-50151"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-50162"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-50163"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-50195"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-53488"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-53489"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-53492"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56852"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56854"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-84304"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-259r-337f-4rfw"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-hrxh-6v49-42gf"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-vh4v-2xq2-g5cg"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25680"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25681"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27136"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-29181"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33186"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33814"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-35206"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-35469"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39821"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39824"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39827"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39828"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39829"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39830"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39831"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39832"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39833"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39834"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39835"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42502"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42506"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42508"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46595"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46597"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46598"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46600"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46680"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-47262"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-48978"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-50151"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-50162"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-50163"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-50195"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-53488"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-53489"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-53492"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56852"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56854"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84304"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "severity": [
        {
          "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "type": "CVSS_V3"
        }
      ],
      "summary": "Helm is a package manager for Charts for Kubernetes",
      "upstream": [
        "CVE-2026-25680",
        "CVE-2026-25681",
        "CVE-2026-27136",
        "CVE-2026-29181",
        "CVE-2026-33186",
        "CVE-2026-33814",
        "CVE-2026-35206",
        "CVE-2026-35469",
        "CVE-2026-39821",
        "CVE-2026-39824",
        "CVE-2026-39827",
        "CVE-2026-39828",
        "CVE-2026-39829",
        "CVE-2026-39830",
        "CVE-2026-39831",
        "CVE-2026-39832",
        "CVE-2026-39833",
        "CVE-2026-39834",
        "CVE-2026-39835",
        "CVE-2026-42502",
        "CVE-2026-42506",
        "CVE-2026-42508",
        "CVE-2026-46595",
        "CVE-2026-46597",
        "CVE-2026-46598",
        "CVE-2026-46600",
        "CVE-2026-46680",
        "CVE-2026-47262",
        "CVE-2026-48978",
        "CVE-2026-50151",
        "CVE-2026-50162",
        "CVE-2026-50163",
        "CVE-2026-50195",
        "CVE-2026-53488",
        "CVE-2026-53489",
        "CVE-2026-53492",
        "CVE-2026-56852",
        "CVE-2026-56854",
        "CVE-2026-84304",
        "ghsa-259r-337f-4rfw",
        "ghsa-hrxh-6v49-42gf",
        "ghsa-vh4v-2xq2-g5cg"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-HA54107 (GHSA-GCJH-H69Q-9W9G)

    Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    Security fixes in tekton-chains 0.25.2-r1
    Details

    Package tekton-chains version 0.25.2-r1 fixes 23 vulnerabilities: ghsa-gcjh-h69q-9w9g, ghsa-pmwq-pjrm-6p5r, CVE-2026-49478, CVE-2026-48702, CVE-2026-49834...

    References

    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "tekton-chains"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "0.25.2-r1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "0.25.2-r1"
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Package tekton-chains version 0.25.2-r1 fixes 23 vulnerabilities: ghsa-gcjh-h69q-9w9g, ghsa-pmwq-pjrm-6p5r, CVE-2026-49478, CVE-2026-48702, CVE-2026-49834...",
      "id": "CLEANSTART-2026-HA54107",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-09-01T11:17:16Z",
      "references": [
        {
          "type": "WEB",
          "url": "https://github.com/tektoncd/chains"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "summary": "Security fixes in tekton-chains 0.25.2-r1",
      "upstream": [
        "ghsa-gcjh-h69q-9w9g",
        "ghsa-pmwq-pjrm-6p5r",
        "CVE-2026-49478",
        "CVE-2026-48702",
        "CVE-2026-49834",
        "CVE-2026-54787",
        "CVE-2026-39984",
        "CVE-2026-49835",
        "CVE-2026-40161",
        "CVE-2026-40938",
        "CVE-2026-25542",
        "CVE-2026-40923",
        "CVE-2026-40924",
        "CVE-2026-2303",
        "CVE-2026-39883",
        "ghsa-hrxh-6v49-42gf",
        "CVE-2026-56864",
        "CVE-2026-56865",
        "ghsa-259r-337f-4rfw",
        "ghsa-3fxj-6jh8-hvhx",
        "ghsa-9g5q-2w5x-hmxf",
        "ghsa-rjr7-jggh-pgcp",
        "CVE-2026-41178"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-HB08666 (CVE-2026-39821)

    Vulnerability from cleanstart – Published: 2026-09-08 01:57 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for CVE-2...
    Details

    Multiple security vulnerabilities affect the dynatrace-operator package. The source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for CVE-2026-46595. See references for individual vulnerability details.


    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "dynatrace-operator"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "1.9.0-r4"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Multiple security vulnerabilities affect the dynatrace-operator package. The source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for CVE-2026-46595. See references for individual vulnerability details.",
      "id": "CLEANSTART-2026-HB08666",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-09-08T01:57:20.508164Z",
      "references": [
        {
          "type": "ADVISORY",
          "url": "https://github.com/cleanstart-dev/cleanstart-security-advisories/tree/main/advisories/2026/CLEANSTART-2026-HB08666.json"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39821"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-41178"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-46600"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56854"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56859"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56860"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56864"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-84304"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-259r-337f-4rfw"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39821"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41178"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46600"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56854"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56859"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56860"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56864"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84304"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "severity": [
        {
          "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "type": "CVSS_V3"
        }
      ],
      "summary": "source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for CVE-2...",
      "upstream": [
        "CVE-2026-39821",
        "CVE-2026-41178",
        "CVE-2026-46600",
        "CVE-2026-56854",
        "CVE-2026-56859",
        "CVE-2026-56860",
        "CVE-2026-56864",
        "CVE-2026-84304",
        "ghsa-259r-337f-4rfw"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-HO97876 (CVE-2026-39821)

    Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    Security fixes in temporal-server 1.30.5-r1
    Details

    Package temporal-server version 1.30.5-r1 fixes 14 vulnerabilities: CVE-2026-39821, CVE-2026-33818, CVE-2026-46600, CVE-2026-56853, CVE-2026-56858...

    References

    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "temporal-server"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "1.30.5-r1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "1.30.5-r1"
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Package temporal-server version 1.30.5-r1 fixes 14 vulnerabilities: CVE-2026-39821, CVE-2026-33818, CVE-2026-46600, CVE-2026-56853, CVE-2026-56858...",
      "id": "CLEANSTART-2026-HO97876",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-09-01T11:17:16Z",
      "references": [
        {
          "type": "WEB",
          "url": "https://github.com/temporalio/temporal"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "summary": "Security fixes in temporal-server 1.30.5-r1",
      "upstream": [
        "CVE-2026-39821",
        "CVE-2026-33818",
        "CVE-2026-46600",
        "CVE-2026-56853",
        "CVE-2026-56858",
        "CVE-2026-56859",
        "CVE-2026-56860",
        "CVE-2026-56862",
        "CVE-2026-5724",
        "CVE-2025-14987",
        "CVE-2025-14986",
        "CVE-2026-5199",
        "ghsa-hrxh-6v49-42gf",
        "ghsa-259r-337f-4rfw"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-HR50080 (CVE-2026-24051)

    Vulnerability from cleanstart – Published: 2026-09-10 02:09 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label
    Details

    Multiple security vulnerabilities affect the cert-manager package. The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. See references for individual vulnerability details.

    References
    https://github.com/cleanstart-dev/cleanstart-secu… ADVISORY
    https://osv.dev/vulnerability/CVE-2026-24051 WEB
    https://osv.dev/vulnerability/CVE-2026-25680 WEB
    https://osv.dev/vulnerability/CVE-2026-25681 WEB
    https://osv.dev/vulnerability/CVE-2026-27136 WEB
    https://osv.dev/vulnerability/CVE-2026-27145 WEB
    https://osv.dev/vulnerability/CVE-2026-32952 WEB
    https://osv.dev/vulnerability/CVE-2026-33186 WEB
    https://osv.dev/vulnerability/CVE-2026-33811 WEB
    https://osv.dev/vulnerability/CVE-2026-33814 WEB
    https://osv.dev/vulnerability/CVE-2026-33818 WEB
    https://osv.dev/vulnerability/CVE-2026-34986 WEB
    https://osv.dev/vulnerability/CVE-2026-39820 WEB
    https://osv.dev/vulnerability/CVE-2026-39821 WEB
    https://osv.dev/vulnerability/CVE-2026-39822 WEB
    https://osv.dev/vulnerability/CVE-2026-39823 WEB
    https://osv.dev/vulnerability/CVE-2026-39824 WEB
    https://osv.dev/vulnerability/CVE-2026-39825 WEB
    https://osv.dev/vulnerability/CVE-2026-39826 WEB
    https://osv.dev/vulnerability/CVE-2026-39827 WEB
    https://osv.dev/vulnerability/CVE-2026-39828 WEB
    https://osv.dev/vulnerability/CVE-2026-39829 WEB
    https://osv.dev/vulnerability/CVE-2026-39830 WEB
    https://osv.dev/vulnerability/CVE-2026-39831 WEB
    https://osv.dev/vulnerability/CVE-2026-39832 WEB
    https://osv.dev/vulnerability/CVE-2026-39833 WEB
    https://osv.dev/vulnerability/CVE-2026-39834 WEB
    https://osv.dev/vulnerability/CVE-2026-39835 WEB
    https://osv.dev/vulnerability/CVE-2026-39836 WEB
    https://osv.dev/vulnerability/CVE-2026-39883 WEB
    https://osv.dev/vulnerability/CVE-2026-41178 WEB
    https://osv.dev/vulnerability/CVE-2026-42499 WEB
    https://osv.dev/vulnerability/CVE-2026-42502 WEB
    https://osv.dev/vulnerability/CVE-2026-42504 WEB
    https://osv.dev/vulnerability/CVE-2026-42505 WEB
    https://osv.dev/vulnerability/CVE-2026-42506 WEB
    https://osv.dev/vulnerability/CVE-2026-42507 WEB
    https://osv.dev/vulnerability/CVE-2026-42508 WEB
    https://osv.dev/vulnerability/CVE-2026-46595 WEB
    https://osv.dev/vulnerability/CVE-2026-46597 WEB
    https://osv.dev/vulnerability/CVE-2026-46598 WEB
    https://osv.dev/vulnerability/CVE-2026-46600 WEB
    https://osv.dev/vulnerability/CVE-2026-56852 WEB
    https://osv.dev/vulnerability/CVE-2026-56853 WEB
    https://osv.dev/vulnerability/CVE-2026-56858 WEB
    https://osv.dev/vulnerability/CVE-2026-56859 WEB
    https://osv.dev/vulnerability/CVE-2026-56860 WEB
    https://osv.dev/vulnerability/CVE-2026-56862 WEB
    https://osv.dev/vulnerability/CVE-2026-73500 WEB
    https://osv.dev/vulnerability/ghsa-259r-337f-4rfw WEB
    https://osv.dev/vulnerability/ghsa-78h2-9frx-2jm8 WEB
    https://osv.dev/vulnerability/ghsa-9h8m-3fm2-qjrq WEB
    https://osv.dev/vulnerability/ghsa-gcjh-h69q-9w9g WEB
    https://osv.dev/vulnerability/ghsa-hrxh-6v49-42gf WEB
    https://osv.dev/vulnerability/ghsa-p77j-4mvh-x3m3 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-24051 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-25680 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-25681 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-27136 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-27145 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-32952 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-33186 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-33811 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-33814 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-33818 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-34986 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39820 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39821 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39822 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39823 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39824 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39825 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39826 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39827 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39828 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39829 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39830 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39831 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39832 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39833 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39834 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39835 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39836 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39883 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-41178 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42499 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42502 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42504 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42505 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42506 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42507 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42508 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-46595 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-46597 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-46598 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-46600 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56852 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56853 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56858 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56859 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56860 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56862 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-73500 WEB

    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "cert-manager"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "1.19.2-r0"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Multiple security vulnerabilities affect the cert-manager package. The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. See references for individual vulnerability details.",
      "id": "CLEANSTART-2026-HR50080",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-09-10T02:09:11.315492Z",
      "references": [
        {
          "type": "ADVISORY",
          "url": "https://github.com/cleanstart-dev/cleanstart-security-advisories/tree/main/advisories/2026/CLEANSTART-2026-HR50080.json"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-24051"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-25680"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-25681"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-27136"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-27145"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-32952"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-33186"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-33811"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-33814"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-33818"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-34986"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39820"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39821"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39822"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39823"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39824"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39825"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39826"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39827"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39828"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39829"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39830"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39831"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39832"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39833"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39834"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39835"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39836"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39883"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-41178"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42499"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42502"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42504"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42505"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42506"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42507"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42508"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-46595"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-46597"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-46598"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-46600"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56852"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56853"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56858"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56859"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56860"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56862"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-73500"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-259r-337f-4rfw"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-78h2-9frx-2jm8"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-9h8m-3fm2-qjrq"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-gcjh-h69q-9w9g"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-hrxh-6v49-42gf"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-p77j-4mvh-x3m3"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-24051"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25680"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25681"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27136"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27145"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32952"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33186"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33811"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33814"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33818"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-34986"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39820"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39821"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39822"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39823"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39824"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39825"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39826"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39827"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39828"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39829"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39830"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39831"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39832"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39833"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39834"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39835"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39836"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39883"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41178"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42499"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42502"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42504"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42505"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42506"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42507"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42508"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46595"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46597"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46598"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46600"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56852"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56853"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56858"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56859"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56860"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56862"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-73500"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "severity": [
        {
          "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "type": "CVSS_V3"
        }
      ],
      "summary": "ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label",
      "upstream": [
        "CVE-2026-24051",
        "CVE-2026-25680",
        "CVE-2026-25681",
        "CVE-2026-27136",
        "CVE-2026-27145",
        "CVE-2026-32952",
        "CVE-2026-33186",
        "CVE-2026-33811",
        "CVE-2026-33814",
        "CVE-2026-33818",
        "CVE-2026-34986",
        "CVE-2026-39820",
        "CVE-2026-39821",
        "CVE-2026-39822",
        "CVE-2026-39823",
        "CVE-2026-39824",
        "CVE-2026-39825",
        "CVE-2026-39826",
        "CVE-2026-39827",
        "CVE-2026-39828",
        "CVE-2026-39829",
        "CVE-2026-39830",
        "CVE-2026-39831",
        "CVE-2026-39832",
        "CVE-2026-39833",
        "CVE-2026-39834",
        "CVE-2026-39835",
        "CVE-2026-39836",
        "CVE-2026-39883",
        "CVE-2026-41178",
        "CVE-2026-42499",
        "CVE-2026-42502",
        "CVE-2026-42504",
        "CVE-2026-42505",
        "CVE-2026-42506",
        "CVE-2026-42507",
        "CVE-2026-42508",
        "CVE-2026-46595",
        "CVE-2026-46597",
        "CVE-2026-46598",
        "CVE-2026-46600",
        "CVE-2026-56852",
        "CVE-2026-56853",
        "CVE-2026-56858",
        "CVE-2026-56859",
        "CVE-2026-56860",
        "CVE-2026-56862",
        "CVE-2026-73500",
        "ghsa-259r-337f-4rfw",
        "ghsa-78h2-9frx-2jm8",
        "ghsa-9h8m-3fm2-qjrq",
        "ghsa-gcjh-h69q-9w9g",
        "ghsa-hrxh-6v49-42gf",
        "ghsa-p77j-4mvh-x3m3"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-IB62904 (CVE-2026-39821)

    Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    Security fixes in temporal-server 1.28.4-r2
    Details

    Package temporal-server version 1.28.4-r2 fixes 15 vulnerabilities: CVE-2026-39821, CVE-2026-33818, CVE-2026-46600, CVE-2026-56853, CVE-2026-56858...

    References

    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "temporal-server"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "1.28.4-r2"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "1.28.4-r2"
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Package temporal-server version 1.28.4-r2 fixes 15 vulnerabilities: CVE-2026-39821, CVE-2026-33818, CVE-2026-46600, CVE-2026-56853, CVE-2026-56858...",
      "id": "CLEANSTART-2026-IB62904",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-09-01T11:17:16Z",
      "references": [
        {
          "type": "WEB",
          "url": "https://github.com/temporalio/temporal"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "summary": "Security fixes in temporal-server 1.28.4-r2",
      "upstream": [
        "CVE-2026-39821",
        "CVE-2026-33818",
        "CVE-2026-46600",
        "CVE-2026-56853",
        "CVE-2026-56858",
        "CVE-2026-56859",
        "CVE-2026-56860",
        "CVE-2026-56862",
        "CVE-2026-5724",
        "CVE-2025-14987",
        "CVE-2025-14986",
        "CVE-2026-5199",
        "ghsa-hrxh-6v49-42gf",
        "ghsa-259r-337f-4rfw",
        "CVE-2026-41178"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-IK56508 (CVE-2026-25680)

    Vulnerability from cleanstart – Published: 2026-09-16 01:01 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection
    Details

    Multiple security vulnerabilities affect the cadvisor package. Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. See references for individual vulnerability details.

    References
    https://github.com/cleanstart-dev/cleanstart-secu… ADVISORY
    https://osv.dev/vulnerability/CVE-2026-25680 WEB
    https://osv.dev/vulnerability/CVE-2026-25681 WEB
    https://osv.dev/vulnerability/CVE-2026-27136 WEB
    https://osv.dev/vulnerability/CVE-2026-27145 WEB
    https://osv.dev/vulnerability/CVE-2026-29181 WEB
    https://osv.dev/vulnerability/CVE-2026-33186 WEB
    https://osv.dev/vulnerability/CVE-2026-33818 WEB
    https://osv.dev/vulnerability/CVE-2026-39821 WEB
    https://osv.dev/vulnerability/CVE-2026-39824 WEB
    https://osv.dev/vulnerability/CVE-2026-39827 WEB
    https://osv.dev/vulnerability/CVE-2026-39828 WEB
    https://osv.dev/vulnerability/CVE-2026-39829 WEB
    https://osv.dev/vulnerability/CVE-2026-39830 WEB
    https://osv.dev/vulnerability/CVE-2026-39831 WEB
    https://osv.dev/vulnerability/CVE-2026-39832 WEB
    https://osv.dev/vulnerability/CVE-2026-39833 WEB
    https://osv.dev/vulnerability/CVE-2026-39834 WEB
    https://osv.dev/vulnerability/CVE-2026-39835 WEB
    https://osv.dev/vulnerability/CVE-2026-41579 WEB
    https://osv.dev/vulnerability/CVE-2026-42502 WEB
    https://osv.dev/vulnerability/CVE-2026-42504 WEB
    https://osv.dev/vulnerability/CVE-2026-42506 WEB
    https://osv.dev/vulnerability/CVE-2026-42507 WEB
    https://osv.dev/vulnerability/CVE-2026-42508 WEB
    https://osv.dev/vulnerability/CVE-2026-46595 WEB
    https://osv.dev/vulnerability/CVE-2026-46597 WEB
    https://osv.dev/vulnerability/CVE-2026-46598 WEB
    https://osv.dev/vulnerability/CVE-2026-46600 WEB
    https://osv.dev/vulnerability/CVE-2026-56853 WEB
    https://osv.dev/vulnerability/CVE-2026-56855 WEB
    https://osv.dev/vulnerability/CVE-2026-56858 WEB
    https://osv.dev/vulnerability/CVE-2026-56859 WEB
    https://osv.dev/vulnerability/CVE-2026-56860 WEB
    https://osv.dev/vulnerability/CVE-2026-56862 WEB
    https://osv.dev/vulnerability/CVE-2026-78662 WEB
    https://osv.dev/vulnerability/CVE-2026-84303 WEB
    https://osv.dev/vulnerability/CVE-2026-84304 WEB
    https://osv.dev/vulnerability/CVE-2026-84445 WEB
    https://osv.dev/vulnerability/ghsa-259r-337f-4rfw WEB
    https://osv.dev/vulnerability/ghsa-hrxh-6v49-42gf WEB
    https://osv.dev/vulnerability/ghsa-mh2q-q3fh-2475 WEB
    https://osv.dev/vulnerability/ghsa-xjvp-4fhw-gc47 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-25680 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-25681 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-27136 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-27145 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-29181 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-33186 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-33818 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39821 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39824 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39827 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39828 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39829 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39830 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39831 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39832 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39833 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39834 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39835 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-41579 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42502 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42504 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42506 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42507 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42508 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-46595 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-46597 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-46598 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-46600 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56853 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56855 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56858 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56859 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56860 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56862 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-78662 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-84303 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-84304 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-84445 WEB

    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "cadvisor"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "0.60.5-r2"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Multiple security vulnerabilities affect the cadvisor package. Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. See references for individual vulnerability details.",
      "id": "CLEANSTART-2026-IK56508",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-09-16T01:01:14.670585Z",
      "references": [
        {
          "type": "ADVISORY",
          "url": "https://github.com/cleanstart-dev/cleanstart-security-advisories/tree/main/advisories/2026/CLEANSTART-2026-IK56508.json"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-25680"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-25681"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-27136"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-27145"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-29181"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-33186"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-33818"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39821"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39824"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39827"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39828"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39829"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39830"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39831"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39832"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39833"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39834"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39835"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-41579"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42502"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42504"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42506"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42507"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42508"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-46595"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-46597"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-46598"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-46600"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56853"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56855"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56858"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56859"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56860"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56862"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-78662"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-84303"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-84304"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-84445"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-259r-337f-4rfw"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-hrxh-6v49-42gf"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-mh2q-q3fh-2475"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-xjvp-4fhw-gc47"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25680"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25681"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27136"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27145"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-29181"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33186"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33818"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39821"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39824"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39827"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39828"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39829"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39830"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39831"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39832"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39833"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39834"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39835"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41579"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42502"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42504"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42506"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42507"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42508"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46595"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46597"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46598"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46600"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56853"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56855"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56858"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56859"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56860"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56862"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78662"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84303"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84304"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84445"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "severity": [
        {
          "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "type": "CVSS_V3"
        }
      ],
      "summary": "Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection",
      "upstream": [
        "CVE-2026-25680",
        "CVE-2026-25681",
        "CVE-2026-27136",
        "CVE-2026-27145",
        "CVE-2026-29181",
        "CVE-2026-33186",
        "CVE-2026-33818",
        "CVE-2026-39821",
        "CVE-2026-39824",
        "CVE-2026-39827",
        "CVE-2026-39828",
        "CVE-2026-39829",
        "CVE-2026-39830",
        "CVE-2026-39831",
        "CVE-2026-39832",
        "CVE-2026-39833",
        "CVE-2026-39834",
        "CVE-2026-39835",
        "CVE-2026-41579",
        "CVE-2026-42502",
        "CVE-2026-42504",
        "CVE-2026-42506",
        "CVE-2026-42507",
        "CVE-2026-42508",
        "CVE-2026-46595",
        "CVE-2026-46597",
        "CVE-2026-46598",
        "CVE-2026-46600",
        "CVE-2026-56853",
        "CVE-2026-56855",
        "CVE-2026-56858",
        "CVE-2026-56859",
        "CVE-2026-56860",
        "CVE-2026-56862",
        "CVE-2026-78662",
        "CVE-2026-84303",
        "CVE-2026-84304",
        "CVE-2026-84445",
        "ghsa-259r-337f-4rfw",
        "ghsa-hrxh-6v49-42gf",
        "ghsa-mh2q-q3fh-2475",
        "ghsa-xjvp-4fhw-gc47"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-IS78554 (GHSA-259R-337F-4RFW)

    Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    Security fixes in ollama-fips 0.32.7-r1
    Details

    Package ollama-fips version 0.32.7-r1 fixes 1 vulnerabilities: ghsa-259r-337f-4rfw

    References

    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "ollama-fips"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "0.32.7-r1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "0.32.7-r1"
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Package ollama-fips version 0.32.7-r1 fixes 1 vulnerabilities: ghsa-259r-337f-4rfw",
      "id": "CLEANSTART-2026-IS78554",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-09-01T11:17:16Z",
      "references": [
        {
          "type": "WEB",
          "url": "https://ollama.com"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "summary": "Security fixes in ollama-fips 0.32.7-r1",
      "upstream": [
        "ghsa-259r-337f-4rfw"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-IW23752 (CVE-2026-56852)

    Vulnerability from cleanstart – Published: 2026-08-13 12:10 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    Security fixes in weaviate-fips 1.38.6-r1
    Details

    Package weaviate-fips version 1.38.6-r1 fixes 3 vulnerabilities: CVE-2026-56852, CVE-2026-46600, ghsa-259r-337f-4rfw

    References

    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "weaviate-fips"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "1.38.6-r1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "1.38.6-r1"
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Package weaviate-fips version 1.38.6-r1 fixes 3 vulnerabilities: CVE-2026-56852, CVE-2026-46600, ghsa-259r-337f-4rfw",
      "id": "CLEANSTART-2026-IW23752",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-08-13T12:10:09Z",
      "references": [
        {
          "type": "WEB",
          "url": "https://github.com/weaviate/weaviate"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "summary": "Security fixes in weaviate-fips 1.38.6-r1",
      "upstream": [
        "CVE-2026-56852",
        "CVE-2026-46600",
        "ghsa-259r-337f-4rfw"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-JC77975 (CVE-2026-46600)

    Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    Security fixes in tempo 2.10.8-r1
    Details

    Package tempo version 2.10.8-r1 fixes 2 vulnerabilities: CVE-2026-46600, ghsa-259r-337f-4rfw

    References

    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "tempo"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "2.10.8-r1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "2.10.8-r1"
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Package tempo version 2.10.8-r1 fixes 2 vulnerabilities: CVE-2026-46600, ghsa-259r-337f-4rfw",
      "id": "CLEANSTART-2026-JC77975",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-09-01T11:17:16Z",
      "references": [
        {
          "type": "WEB",
          "url": "https://github.com/grafana/tempo"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "summary": "Security fixes in tempo 2.10.8-r1",
      "upstream": [
        "CVE-2026-46600",
        "ghsa-259r-337f-4rfw"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-JD10612 (CVE-2026-2303)

    Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    Security fixes in karma 0.130-r1
    Details

    Package karma version 0.130-r1 fixes 6 vulnerabilities: CVE-2026-2303, CVE-2026-39824, ghsa-259r-337f-4rfw, ghsa-3fxj-6jh8-hvhx, ghsa-9g5q-2w5x-hmxf...

    References

    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "karma"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "0.130-r1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "0.130-r1"
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Package karma version 0.130-r1 fixes 6 vulnerabilities: CVE-2026-2303, CVE-2026-39824, ghsa-259r-337f-4rfw, ghsa-3fxj-6jh8-hvhx, ghsa-9g5q-2w5x-hmxf...",
      "id": "CLEANSTART-2026-JD10612",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-09-01T11:17:16Z",
      "references": [
        {
          "type": "WEB",
          "url": "https://github.com/prymitive/karma.git"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "summary": "Security fixes in karma 0.130-r1",
      "upstream": [
        "CVE-2026-2303",
        "CVE-2026-39824",
        "ghsa-259r-337f-4rfw",
        "ghsa-3fxj-6jh8-hvhx",
        "ghsa-9g5q-2w5x-hmxf",
        "ghsa-rjr7-jggh-pgcp"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-JM50700 (GHSA-259R-337F-4RFW)

    Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    Security fixes in ollama-fips 0.32.4-r1
    Details

    Package ollama-fips version 0.32.4-r1 fixes 1 vulnerabilities: ghsa-259r-337f-4rfw

    References

    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "ollama-fips"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "0.32.4-r1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "0.32.4-r1"
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Package ollama-fips version 0.32.4-r1 fixes 1 vulnerabilities: ghsa-259r-337f-4rfw",
      "id": "CLEANSTART-2026-JM50700",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-09-01T11:17:16Z",
      "references": [
        {
          "type": "WEB",
          "url": "https://ollama.com"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "summary": "Security fixes in ollama-fips 0.32.4-r1",
      "upstream": [
        "ghsa-259r-337f-4rfw"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-JX39152 (CVE-2026-49834)

    Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    Security fixes in spire-server 1.14.7-r0
    Details

    Package spire-server version 1.14.7-r0 fixes 16 vulnerabilities: CVE-2026-49834, CVE-2026-24122, CVE-2026-39395, CVE-2026-41178, CVE-2026-41568...

    References

    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "spire-server"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "1.14.7-r0"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "1.14.7-r0"
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Package spire-server version 1.14.7-r0 fixes 16 vulnerabilities: CVE-2026-49834, CVE-2026-24122, CVE-2026-39395, CVE-2026-41178, CVE-2026-41568...",
      "id": "CLEANSTART-2026-JX39152",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-09-01T11:17:16Z",
      "references": [
        {
          "type": "WEB",
          "url": "https://github.com/spiffe/spire"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "summary": "Security fixes in spire-server 1.14.7-r0",
      "upstream": [
        "CVE-2026-49834",
        "CVE-2026-24122",
        "CVE-2026-39395",
        "CVE-2026-41178",
        "CVE-2026-41568",
        "CVE-2026-41889",
        "CVE-2026-48702",
        "CVE-2026-49834",
        "CVE-2026-49835",
        "CVE-2026-54787",
        "CVE-2026-56864",
        "CVE-2026-56865",
        "ghsa-259r-337f-4rfw",
        "ghsa-3fxj-6jh8-hvhx",
        "ghsa-9g5q-2w5x-hmxf",
        "ghsa-rjr7-jggh-pgcp"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-KI63132 (GHSA-HRXH-6V49-42GF)

    Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    Security fixes in prometheus-fips 3.12.0-r1
    Details

    Package prometheus-fips version 3.12.0-r1 fixes 2 vulnerabilities: ghsa-hrxh-6v49-42gf, ghsa-259r-337f-4rfw


    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "prometheus-fips"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "3.12.0-r1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "3.12.0-r1"
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Package prometheus-fips version 3.12.0-r1 fixes 2 vulnerabilities: ghsa-hrxh-6v49-42gf, ghsa-259r-337f-4rfw",
      "id": "CLEANSTART-2026-KI63132",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-09-01T11:17:16Z",
      "references": [
        {
          "type": "WEB",
          "url": "https://github.com/prometheus/prometheus"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "summary": "Security fixes in prometheus-fips 3.12.0-r1",
      "upstream": [
        "ghsa-hrxh-6v49-42gf",
        "ghsa-259r-337f-4rfw"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-KP10631 (CVE-2025-22868)

    Vulnerability from cleanstart – Published: 2026-09-10 00:42 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for CVE-2...
    Details

    Multiple security vulnerabilities affect the vault-k8s package. The source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for CVE-2026-46595. See references for individual vulnerability details.


    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "vault-k8s"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "1.5.0.r4"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Multiple security vulnerabilities affect the vault-k8s package. The source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for CVE-2026-46595. See references for individual vulnerability details.",
      "id": "CLEANSTART-2026-KP10631",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-09-10T00:42:34.310130Z",
      "references": [
        {
          "type": "ADVISORY",
          "url": "https://github.com/cleanstart-dev/cleanstart-security-advisories/tree/main/advisories/2026/CLEANSTART-2026-KP10631.json"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-22868"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-33818"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39821"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-46600"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56853"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56854"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56858"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56859"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56860"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56862"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-259r-337f-4rfw"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-6v2p-p543-phr9"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22868"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33818"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39821"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46600"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56853"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56854"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56858"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56859"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56860"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56862"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "severity": [
        {
          "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "type": "CVSS_V3"
        }
      ],
      "summary": "source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for CVE-2...",
      "upstream": [
        "CVE-2025-22868",
        "CVE-2026-33818",
        "CVE-2026-39821",
        "CVE-2026-46600",
        "CVE-2026-56853",
        "CVE-2026-56854",
        "CVE-2026-56858",
        "CVE-2026-56859",
        "CVE-2026-56860",
        "CVE-2026-56862",
        "ghsa-259r-337f-4rfw",
        "ghsa-6v2p-p543-phr9"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-KP99907 (CVE-2026-56864)

    Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    Security fixes in crossplane 2.3.4-r2
    Details

    Package crossplane version 2.3.4-r2 fixes 4 vulnerabilities: CVE-2026-56864, CVE-2026-56865, ghsa-259r-337f-4rfw, CVE-2026-54787


    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "crossplane"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "2.3.4-r2"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "2.3.4-r2"
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Package crossplane version 2.3.4-r2 fixes 4 vulnerabilities: CVE-2026-56864, CVE-2026-56865, ghsa-259r-337f-4rfw, CVE-2026-54787",
      "id": "CLEANSTART-2026-KP99907",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-09-01T11:17:16Z",
      "references": [
        {
          "type": "WEB",
          "url": "https://github.com/crossplane/crossplane"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "summary": "Security fixes in crossplane 2.3.4-r2",
      "upstream": [
        "CVE-2026-56864",
        "CVE-2026-56865",
        "ghsa-259r-337f-4rfw",
        "CVE-2026-54787"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-KQ21500 (GHSA-R277-6W6Q-XMQW)

    Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    Security fixes in grafana 12.3.10-r1
    Details

    Package grafana version 12.3.10-r1 fixes 15 vulnerabilities: ghsa-r277-6w6q-xmqw, ghsa-jpcw-4wr7-c3vq, ghsa-gcjh-h69q-9w9g, CVE-2026-21728, CVE-2026-28377...

    References

    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "grafana"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "12.3.10-r1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "12.3.10-r1"
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Package grafana version 12.3.10-r1 fixes 15 vulnerabilities: ghsa-r277-6w6q-xmqw, ghsa-jpcw-4wr7-c3vq, ghsa-gcjh-h69q-9w9g, CVE-2026-21728, CVE-2026-28377...",
      "id": "CLEANSTART-2026-KQ21500",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-09-01T11:17:16Z",
      "references": [
        {
          "type": "WEB",
          "url": "https://grafana.com"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "summary": "Security fixes in grafana 12.3.10-r1",
      "upstream": [
        "ghsa-r277-6w6q-xmqw",
        "ghsa-jpcw-4wr7-c3vq",
        "ghsa-gcjh-h69q-9w9g",
        "CVE-2026-21728",
        "CVE-2026-28377",
        "CVE-2026-48096",
        "CVE-2026-55689",
        "CVE-2026-55170",
        "CVE-2026-42151",
        "CVE-2026-44903",
        "CVE-2026-40179",
        "CVE-2026-2303",
        "CVE-2026-39882",
        "ghsa-259r-337f-4rfw",
        "CVE-2026-41178"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-KQ31223 (CVE-2026-2303)

    Vulnerability from cleanstart – Published: 2026-09-18 01:30 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    gRPC-Go is the Go language implementation of gRPC
    Details

    Multiple security vulnerabilities affect the vault package. gRPC-Go is the Go language implementation of gRPC. See references for individual vulnerability details.

    References
    https://github.com/cleanstart-dev/cleanstart-secu… ADVISORY
    https://osv.dev/vulnerability/CVE-2026-2303 WEB
    https://osv.dev/vulnerability/CVE-2026-25680 WEB
    https://osv.dev/vulnerability/CVE-2026-25681 WEB
    https://osv.dev/vulnerability/CVE-2026-27136 WEB
    https://osv.dev/vulnerability/CVE-2026-27145 WEB
    https://osv.dev/vulnerability/CVE-2026-32280 WEB
    https://osv.dev/vulnerability/CVE-2026-32281 WEB
    https://osv.dev/vulnerability/CVE-2026-32282 WEB
    https://osv.dev/vulnerability/CVE-2026-32283 WEB
    https://osv.dev/vulnerability/CVE-2026-32288 WEB
    https://osv.dev/vulnerability/CVE-2026-32289 WEB
    https://osv.dev/vulnerability/CVE-2026-32952 WEB
    https://osv.dev/vulnerability/CVE-2026-33186 WEB
    https://osv.dev/vulnerability/CVE-2026-33810 WEB
    https://osv.dev/vulnerability/CVE-2026-33811 WEB
    https://osv.dev/vulnerability/CVE-2026-33814 WEB
    https://osv.dev/vulnerability/CVE-2026-33816 WEB
    https://osv.dev/vulnerability/CVE-2026-33818 WEB
    https://osv.dev/vulnerability/CVE-2026-34040 WEB
    https://osv.dev/vulnerability/CVE-2026-34986 WEB
    https://osv.dev/vulnerability/CVE-2026-39817 WEB
    https://osv.dev/vulnerability/CVE-2026-39819 WEB
    https://osv.dev/vulnerability/CVE-2026-39820 WEB
    https://osv.dev/vulnerability/CVE-2026-39821 WEB
    https://osv.dev/vulnerability/CVE-2026-39822 WEB
    https://osv.dev/vulnerability/CVE-2026-39823 WEB
    https://osv.dev/vulnerability/CVE-2026-39824 WEB
    https://osv.dev/vulnerability/CVE-2026-39825 WEB
    https://osv.dev/vulnerability/CVE-2026-39826 WEB
    https://osv.dev/vulnerability/CVE-2026-39827 WEB
    https://osv.dev/vulnerability/CVE-2026-39828 WEB
    https://osv.dev/vulnerability/CVE-2026-39829 WEB
    https://osv.dev/vulnerability/CVE-2026-39830 WEB
    https://osv.dev/vulnerability/CVE-2026-39831 WEB
    https://osv.dev/vulnerability/CVE-2026-39832 WEB
    https://osv.dev/vulnerability/CVE-2026-39833 WEB
    https://osv.dev/vulnerability/CVE-2026-39834 WEB
    https://osv.dev/vulnerability/CVE-2026-39835 WEB
    https://osv.dev/vulnerability/CVE-2026-39836 WEB
    https://osv.dev/vulnerability/CVE-2026-39883 WEB
    https://osv.dev/vulnerability/CVE-2026-41178 WEB
    https://osv.dev/vulnerability/CVE-2026-41602 WEB
    https://osv.dev/vulnerability/CVE-2026-41889 WEB
    https://osv.dev/vulnerability/CVE-2026-42499 WEB
    https://osv.dev/vulnerability/CVE-2026-42501 WEB
    https://osv.dev/vulnerability/CVE-2026-42502 WEB
    https://osv.dev/vulnerability/CVE-2026-42504 WEB
    https://osv.dev/vulnerability/CVE-2026-42505 WEB
    https://osv.dev/vulnerability/CVE-2026-42506 WEB
    https://osv.dev/vulnerability/CVE-2026-42507 WEB
    https://osv.dev/vulnerability/CVE-2026-42508 WEB
    https://osv.dev/vulnerability/CVE-2026-43871 WEB
    https://osv.dev/vulnerability/CVE-2026-44503 WEB
    https://osv.dev/vulnerability/CVE-2026-46595 WEB
    https://osv.dev/vulnerability/CVE-2026-46597 WEB
    https://osv.dev/vulnerability/CVE-2026-46598 WEB
    https://osv.dev/vulnerability/CVE-2026-46600 WEB
    https://osv.dev/vulnerability/CVE-2026-56852 WEB
    https://osv.dev/vulnerability/CVE-2026-56853 WEB
    https://osv.dev/vulnerability/CVE-2026-56855 WEB
    https://osv.dev/vulnerability/CVE-2026-56858 WEB
    https://osv.dev/vulnerability/CVE-2026-56859 WEB
    https://osv.dev/vulnerability/CVE-2026-56860 WEB
    https://osv.dev/vulnerability/CVE-2026-56862 WEB
    https://osv.dev/vulnerability/CVE-2026-73500 WEB
    https://osv.dev/vulnerability/CVE-2026-78662 WEB
    https://osv.dev/vulnerability/CVE-2026-84304 WEB
    https://osv.dev/vulnerability/CVE-2026-84445 WEB
    https://osv.dev/vulnerability/ghsa-259r-337f-4rfw WEB
    https://osv.dev/vulnerability/ghsa-7j59-v9qr-6fq9 WEB
    https://osv.dev/vulnerability/ghsa-cp6g-7hqx-qxhp WEB
    https://osv.dev/vulnerability/ghsa-hrxh-6v49-42gf WEB
    https://osv.dev/vulnerability/ghsa-j88v-2chj-qfwx WEB
    https://osv.dev/vulnerability/ghsa-p77j-4mvh-x3m3 WEB
    https://osv.dev/vulnerability/ghsa-pjcq-xvwq-hhpj WEB
    https://osv.dev/vulnerability/ghsa-wf45-q9ch-q8gh WEB
    https://osv.dev/vulnerability/ghsa-xmrv-pmrh-hhx2 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-2303 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-25680 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-25681 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-27136 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-27145 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-32280 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-32281 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-32282 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-32283 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-32288 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-32289 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-32952 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-33186 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-33810 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-33811 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-33814 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-33816 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-33818 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-34040 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-34986 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39817 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39819 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39820 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39821 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39822 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39823 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39824 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39825 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39826 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39827 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39828 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39829 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39830 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39831 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39832 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39833 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39834 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39835 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39836 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39883 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-41178 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-41602 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-41889 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42499 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42501 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42502 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42504 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42505 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42506 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42507 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42508 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-43871 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-44503 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-46595 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-46597 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-46598 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-46600 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56852 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56853 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56855 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56858 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56859 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56860 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56862 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-73500 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-78662 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-84304 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-84445 WEB

    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "vault"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "1.21.4-r9"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Multiple security vulnerabilities affect the vault package. gRPC-Go is the Go language implementation of gRPC. See references for individual vulnerability details.",
      "id": "CLEANSTART-2026-KQ31223",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-09-18T01:30:00.429155Z",
      "references": [
        {
          "type": "ADVISORY",
          "url": "https://github.com/cleanstart-dev/cleanstart-security-advisories/tree/main/advisories/2026/CLEANSTART-2026-KQ31223.json"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-2303"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-25680"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-25681"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-27136"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-27145"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-32280"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-32281"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-32282"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-32283"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-32288"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-32289"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-32952"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-33186"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-33810"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-33811"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-33814"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-33816"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-33818"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-34040"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-34986"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39817"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39819"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39820"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39821"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39822"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39823"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39824"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39825"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39826"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39827"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39828"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39829"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39830"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39831"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39832"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39833"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39834"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39835"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39836"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39883"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-41178"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-41602"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-41889"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42499"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42501"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42502"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42504"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42505"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42506"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42507"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42508"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-43871"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-44503"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-46595"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-46597"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-46598"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-46600"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56852"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56853"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56855"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56858"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56859"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56860"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56862"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-73500"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-78662"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-84304"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-84445"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-259r-337f-4rfw"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-7j59-v9qr-6fq9"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-cp6g-7hqx-qxhp"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-hrxh-6v49-42gf"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-j88v-2chj-qfwx"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-p77j-4mvh-x3m3"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-pjcq-xvwq-hhpj"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-wf45-q9ch-q8gh"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-xmrv-pmrh-hhx2"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-2303"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25680"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25681"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27136"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27145"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32280"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32281"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32282"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32283"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32288"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32289"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32952"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33186"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33810"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33811"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33814"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33816"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33818"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-34040"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-34986"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39817"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39819"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39820"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39821"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39822"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39823"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39824"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39825"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39826"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39827"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39828"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39829"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39830"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39831"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39832"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39833"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39834"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39835"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39836"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39883"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41178"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41602"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41889"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42499"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42501"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42502"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42504"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42505"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42506"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42507"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42508"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-43871"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-44503"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46595"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46597"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46598"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46600"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56852"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56853"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56855"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56858"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56859"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56860"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56862"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-73500"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78662"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84304"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84445"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "severity": [
        {
          "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "type": "CVSS_V3"
        }
      ],
      "summary": "gRPC-Go is the Go language implementation of gRPC",
      "upstream": [
        "CVE-2026-2303",
        "CVE-2026-25680",
        "CVE-2026-25681",
        "CVE-2026-27136",
        "CVE-2026-27145",
        "CVE-2026-32280",
        "CVE-2026-32281",
        "CVE-2026-32282",
        "CVE-2026-32283",
        "CVE-2026-32288",
        "CVE-2026-32289",
        "CVE-2026-32952",
        "CVE-2026-33186",
        "CVE-2026-33810",
        "CVE-2026-33811",
        "CVE-2026-33814",
        "CVE-2026-33816",
        "CVE-2026-33818",
        "CVE-2026-34040",
        "CVE-2026-34986",
        "CVE-2026-39817",
        "CVE-2026-39819",
        "CVE-2026-39820",
        "CVE-2026-39821",
        "CVE-2026-39822",
        "CVE-2026-39823",
        "CVE-2026-39824",
        "CVE-2026-39825",
        "CVE-2026-39826",
        "CVE-2026-39827",
        "CVE-2026-39828",
        "CVE-2026-39829",
        "CVE-2026-39830",
        "CVE-2026-39831",
        "CVE-2026-39832",
        "CVE-2026-39833",
        "CVE-2026-39834",
        "CVE-2026-39835",
        "CVE-2026-39836",
        "CVE-2026-39883",
        "CVE-2026-41178",
        "CVE-2026-41602",
        "CVE-2026-41889",
        "CVE-2026-42499",
        "CVE-2026-42501",
        "CVE-2026-42502",
        "CVE-2026-42504",
        "CVE-2026-42505",
        "CVE-2026-42506",
        "CVE-2026-42507",
        "CVE-2026-42508",
        "CVE-2026-43871",
        "CVE-2026-44503",
        "CVE-2026-46595",
        "CVE-2026-46597",
        "CVE-2026-46598",
        "CVE-2026-46600",
        "CVE-2026-56852",
        "CVE-2026-56853",
        "CVE-2026-56855",
        "CVE-2026-56858",
        "CVE-2026-56859",
        "CVE-2026-56860",
        "CVE-2026-56862",
        "CVE-2026-73500",
        "CVE-2026-78662",
        "CVE-2026-84304",
        "CVE-2026-84445",
        "ghsa-259r-337f-4rfw",
        "ghsa-7j59-v9qr-6fq9",
        "ghsa-cp6g-7hqx-qxhp",
        "ghsa-hrxh-6v49-42gf",
        "ghsa-j88v-2chj-qfwx",
        "ghsa-p77j-4mvh-x3m3",
        "ghsa-pjcq-xvwq-hhpj",
        "ghsa-wf45-q9ch-q8gh",
        "ghsa-xmrv-pmrh-hhx2"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-KR69944 (CVE-2025-61732)

    Vulnerability from cleanstart – Published: 2026-09-10 01:56 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for CVE-2...
    Details

    Multiple security vulnerabilities affect the haproxy-ingress package. The source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for CVE-2026-46595. See references for individual vulnerability details.

    References
    https://github.com/cleanstart-dev/cleanstart-secu… ADVISORY
    https://osv.dev/vulnerability/CVE-2025-61732 WEB
    https://osv.dev/vulnerability/CVE-2025-68121 WEB
    https://osv.dev/vulnerability/CVE-2026-25679 WEB
    https://osv.dev/vulnerability/CVE-2026-25680 WEB
    https://osv.dev/vulnerability/CVE-2026-25681 WEB
    https://osv.dev/vulnerability/CVE-2026-27136 WEB
    https://osv.dev/vulnerability/CVE-2026-27139 WEB
    https://osv.dev/vulnerability/CVE-2026-27142 WEB
    https://osv.dev/vulnerability/CVE-2026-33814 WEB
    https://osv.dev/vulnerability/CVE-2026-33818 WEB
    https://osv.dev/vulnerability/CVE-2026-39821 WEB
    https://osv.dev/vulnerability/CVE-2026-39824 WEB
    https://osv.dev/vulnerability/CVE-2026-39827 WEB
    https://osv.dev/vulnerability/CVE-2026-39828 WEB
    https://osv.dev/vulnerability/CVE-2026-39829 WEB
    https://osv.dev/vulnerability/CVE-2026-39830 WEB
    https://osv.dev/vulnerability/CVE-2026-39831 WEB
    https://osv.dev/vulnerability/CVE-2026-39832 WEB
    https://osv.dev/vulnerability/CVE-2026-39833 WEB
    https://osv.dev/vulnerability/CVE-2026-39834 WEB
    https://osv.dev/vulnerability/CVE-2026-39835 WEB
    https://osv.dev/vulnerability/CVE-2026-42502 WEB
    https://osv.dev/vulnerability/CVE-2026-42506 WEB
    https://osv.dev/vulnerability/CVE-2026-42508 WEB
    https://osv.dev/vulnerability/CVE-2026-46595 WEB
    https://osv.dev/vulnerability/CVE-2026-46597 WEB
    https://osv.dev/vulnerability/CVE-2026-46598 WEB
    https://osv.dev/vulnerability/CVE-2026-46600 WEB
    https://osv.dev/vulnerability/CVE-2026-56852 WEB
    https://osv.dev/vulnerability/CVE-2026-56853 WEB
    https://osv.dev/vulnerability/CVE-2026-56854 WEB
    https://osv.dev/vulnerability/CVE-2026-56858 WEB
    https://osv.dev/vulnerability/CVE-2026-56859 WEB
    https://osv.dev/vulnerability/CVE-2026-56860 WEB
    https://osv.dev/vulnerability/CVE-2026-56862 WEB
    https://osv.dev/vulnerability/ghsa-259r-337f-4rfw WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-61732 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-68121 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-25679 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-25680 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-25681 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-27136 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-27139 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-27142 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-33814 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-33818 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39821 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39824 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39827 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39828 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39829 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39830 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39831 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39832 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39833 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39834 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39835 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42502 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42506 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42508 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-46595 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-46597 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-46598 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-46600 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56852 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56853 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56854 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56858 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56859 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56860 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56862 WEB

    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "haproxy-ingress"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "0.15.1-r0"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Multiple security vulnerabilities affect the haproxy-ingress package. The source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for CVE-2026-46595. See references for individual vulnerability details.",
      "id": "CLEANSTART-2026-KR69944",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-09-10T01:56:39.852336Z",
      "references": [
        {
          "type": "ADVISORY",
          "url": "https://github.com/cleanstart-dev/cleanstart-security-advisories/tree/main/advisories/2026/CLEANSTART-2026-KR69944.json"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-61732"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-68121"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-25679"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-25680"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-25681"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-27136"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-27139"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-27142"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-33814"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-33818"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39821"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39824"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39827"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39828"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39829"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39830"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39831"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39832"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39833"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39834"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39835"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42502"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42506"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42508"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-46595"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-46597"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-46598"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-46600"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56852"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56853"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56854"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56858"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56859"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56860"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56862"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-259r-337f-4rfw"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61732"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-68121"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25679"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25680"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25681"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27136"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27139"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27142"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33814"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33818"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39821"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39824"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39827"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39828"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39829"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39830"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39831"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39832"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39833"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39834"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39835"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42502"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42506"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42508"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46595"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46597"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46598"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46600"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56852"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56853"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56854"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56858"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56859"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56860"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56862"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "severity": [
        {
          "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "type": "CVSS_V3"
        }
      ],
      "summary": "source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for CVE-2...",
      "upstream": [
        "CVE-2025-61732",
        "CVE-2025-68121",
        "CVE-2026-25679",
        "CVE-2026-25680",
        "CVE-2026-25681",
        "CVE-2026-27136",
        "CVE-2026-27139",
        "CVE-2026-27142",
        "CVE-2026-33814",
        "CVE-2026-33818",
        "CVE-2026-39821",
        "CVE-2026-39824",
        "CVE-2026-39827",
        "CVE-2026-39828",
        "CVE-2026-39829",
        "CVE-2026-39830",
        "CVE-2026-39831",
        "CVE-2026-39832",
        "CVE-2026-39833",
        "CVE-2026-39834",
        "CVE-2026-39835",
        "CVE-2026-42502",
        "CVE-2026-42506",
        "CVE-2026-42508",
        "CVE-2026-46595",
        "CVE-2026-46597",
        "CVE-2026-46598",
        "CVE-2026-46600",
        "CVE-2026-56852",
        "CVE-2026-56853",
        "CVE-2026-56854",
        "CVE-2026-56858",
        "CVE-2026-56859",
        "CVE-2026-56860",
        "CVE-2026-56862",
        "ghsa-259r-337f-4rfw"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-KT57055 (GHSA-259R-337F-4RFW)

    Vulnerability from cleanstart – Published: 2026-08-13 12:10 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    Security fixes in knative-serving 1.20.3-r0
    Details

    Package knative-serving version 1.20.3-r0 fixes 2 vulnerabilities: ghsa-259r-337f-4rfw, CVE-2026-41178

    References

    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "knative-serving"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "1.20.3-r0"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "1.20.3-r0"
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Package knative-serving version 1.20.3-r0 fixes 2 vulnerabilities: ghsa-259r-337f-4rfw, CVE-2026-41178",
      "id": "CLEANSTART-2026-KT57055",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-08-13T12:10:09Z",
      "references": [
        {
          "type": "WEB",
          "url": "https://knative.dev/docs/serving/"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "summary": "Security fixes in knative-serving 1.20.3-r0",
      "upstream": [
        "ghsa-259r-337f-4rfw",
        "CVE-2026-41178"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-LC64978 (CVE-2026-26958)

    Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    Security fixes in tkn 0.43.2-r1
    Details

    Package tkn version 0.43.2-r1 fixes 59 vulnerabilities: CVE-2026-26958, CVE-2025-15558, CVE-2026-34040, CVE-2026-33997, CVE-2025-69725...

    References

    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "tkn"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "0.43.2-r1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "0.43.2-r1"
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Package tkn version 0.43.2-r1 fixes 59 vulnerabilities: CVE-2026-26958, CVE-2025-15558, CVE-2026-34040, CVE-2026-33997, CVE-2025-69725...",
      "id": "CLEANSTART-2026-LC64978",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-09-01T11:17:16Z",
      "references": [
        {
          "type": "WEB",
          "url": "https://github.com/tektoncd/cli"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "summary": "Security fixes in tkn 0.43.2-r1",
      "upstream": [
        "CVE-2026-26958",
        "CVE-2025-15558",
        "CVE-2026-34040",
        "CVE-2026-33997",
        "CVE-2025-69725",
        "ghsa-gcjh-h69q-9w9g",
        "ghsa-pmwq-pjrm-6p5r",
        "CVE-2026-49478",
        "CVE-2026-22772",
        "CVE-2026-48702",
        "CVE-2026-23831",
        "CVE-2026-24117",
        "CVE-2026-24137",
        "CVE-2026-54787",
        "CVE-2026-49834",
        "CVE-2026-49835",
        "CVE-2026-39984",
        "CVE-2026-24686",
        "CVE-2026-23991",
        "CVE-2026-23992",
        "CVE-2026-2303",
        "CVE-2026-29181",
        "CVE-2026-39883",
        "CVE-2026-46597",
        "CVE-2026-39828",
        "CVE-2026-39829",
        "CVE-2026-39830",
        "CVE-2026-39831",
        "CVE-2026-39832",
        "CVE-2026-39835",
        "CVE-2026-42508",
        "CVE-2026-46595",
        "CVE-2026-39827",
        "CVE-2026-39833",
        "CVE-2026-39834",
        "CVE-2026-46598",
        "CVE-2026-27136",
        "CVE-2026-25681",
        "CVE-2026-33814",
        "CVE-2026-39821",
        "CVE-2026-46600",
        "CVE-2026-25680",
        "CVE-2026-42502",
        "CVE-2026-42506",
        "CVE-2026-39824",
        "CVE-2026-56852",
        "ghsa-hrxh-6v49-42gf",
        "CVE-2026-33818",
        "CVE-2026-56853",
        "CVE-2026-56858",
        "CVE-2026-56859",
        "CVE-2026-56860",
        "CVE-2026-56862",
        "CVE-2026-56864",
        "CVE-2026-56865",
        "ghsa-259r-337f-4rfw",
        "ghsa-3fxj-6jh8-hvhx",
        "ghsa-9g5q-2w5x-hmxf",
        "ghsa-rjr7-jggh-pgcp"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-LE16402 (CVE-2026-50195)

    Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    Security fixes in rancher-agent 2.13.7-r1
    Details

    Package rancher-agent version 2.13.7-r1 fixes 18 vulnerabilities: CVE-2026-50195, CVE-2026-53492, CVE-2026-53489, CVE-2026-46680, CVE-2026-53488...

    References

    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "rancher-agent"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "2.13.7-r1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "2.13.7-r1"
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Package rancher-agent version 2.13.7-r1 fixes 18 vulnerabilities: CVE-2026-50195, CVE-2026-53492, CVE-2026-53489, CVE-2026-46680, CVE-2026-53488...",
      "id": "CLEANSTART-2026-LE16402",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-09-01T11:17:16Z",
      "references": [
        {
          "type": "WEB",
          "url": "https://github.com/rancher/rancher"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "summary": "Security fixes in rancher-agent 2.13.7-r1",
      "upstream": [
        "CVE-2026-50195",
        "CVE-2026-53492",
        "CVE-2026-53489",
        "CVE-2026-46680",
        "CVE-2026-53488",
        "CVE-2026-47262",
        "ghsa-hrxh-6v49-42gf",
        "CVE-2026-56864",
        "CVE-2026-56865",
        "CVE-2026-56852",
        "CVE-2026-48978",
        "CVE-2026-50163",
        "CVE-2026-50151",
        "CVE-2026-50162",
        "ghsa-vh4v-2xq2-g5cg",
        "ghsa-gcjh-h69q-9w9g",
        "CVE-2026-41178",
        "ghsa-259r-337f-4rfw"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-LE73008 (CVE-2025-61729)

    Vulnerability from cleanstart – Published: 2026-09-10 00:49 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter value overflows the message buffer
    Details

    Multiple security vulnerabilities affect the prometheus-redis-exporter package. Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter value overflows the message buffer. See references for individual vulnerability details.


    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "prometheus-redis-exporter"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "1.86.0-r2"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Multiple security vulnerabilities affect the prometheus-redis-exporter package. Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter value overflows the message buffer. See references for individual vulnerability details.",
      "id": "CLEANSTART-2026-LE73008",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-09-10T00:49:04.850219Z",
      "references": [
        {
          "type": "ADVISORY",
          "url": "https://github.com/cleanstart-dev/cleanstart-security-advisories/tree/main/advisories/2026/CLEANSTART-2026-LE73008.json"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-61729"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-33818"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39821"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39822"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42505"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-46600"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56853"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56858"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56859"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56860"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56862"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-259r-337f-4rfw"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61729"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33818"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39821"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39822"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42505"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46600"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56853"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56858"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56859"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56860"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56862"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "severity": [
        {
          "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "type": "CVSS_V3"
        }
      ],
      "summary": "Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter value overflows the message buffer",
      "upstream": [
        "CVE-2025-61729",
        "CVE-2026-33818",
        "CVE-2026-39821",
        "CVE-2026-39822",
        "CVE-2026-42505",
        "CVE-2026-46600",
        "CVE-2026-56853",
        "CVE-2026-56858",
        "CVE-2026-56859",
        "CVE-2026-56860",
        "CVE-2026-56862",
        "ghsa-259r-337f-4rfw"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-LJ43739 (CVE-2026-14362)

    Vulnerability from cleanstart – Published: 2026-09-08 00:47 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    HashiCorp memberlist before version 0
    Details

    Multiple security vulnerabilities affect the weaviate-fips package. HashiCorp memberlist before version 0. See references for individual vulnerability details.

    References
    https://github.com/cleanstart-dev/cleanstart-secu… ADVISORY
    https://osv.dev/vulnerability/CVE-2026-14362 WEB
    https://osv.dev/vulnerability/CVE-2026-2303 WEB
    https://osv.dev/vulnerability/CVE-2026-25680 WEB
    https://osv.dev/vulnerability/CVE-2026-25681 WEB
    https://osv.dev/vulnerability/CVE-2026-27136 WEB
    https://osv.dev/vulnerability/CVE-2026-39821 WEB
    https://osv.dev/vulnerability/CVE-2026-39827 WEB
    https://osv.dev/vulnerability/CVE-2026-39828 WEB
    https://osv.dev/vulnerability/CVE-2026-39829 WEB
    https://osv.dev/vulnerability/CVE-2026-39830 WEB
    https://osv.dev/vulnerability/CVE-2026-39831 WEB
    https://osv.dev/vulnerability/CVE-2026-39832 WEB
    https://osv.dev/vulnerability/CVE-2026-39833 WEB
    https://osv.dev/vulnerability/CVE-2026-39834 WEB
    https://osv.dev/vulnerability/CVE-2026-39835 WEB
    https://osv.dev/vulnerability/CVE-2026-42502 WEB
    https://osv.dev/vulnerability/CVE-2026-42506 WEB
    https://osv.dev/vulnerability/CVE-2026-42508 WEB
    https://osv.dev/vulnerability/CVE-2026-46595 WEB
    https://osv.dev/vulnerability/CVE-2026-46597 WEB
    https://osv.dev/vulnerability/CVE-2026-46598 WEB
    https://osv.dev/vulnerability/CVE-2026-46600 WEB
    https://osv.dev/vulnerability/CVE-2026-56852 WEB
    https://osv.dev/vulnerability/ghsa-259r-337f-4rfw WEB
    https://osv.dev/vulnerability/ghsa-cp6g-7hqx-qxhp WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-14362 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-2303 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-25680 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-25681 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-27136 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39821 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39827 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39828 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39829 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39830 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39831 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39832 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39833 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39834 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39835 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42502 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42506 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42508 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-46595 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-46597 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-46598 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-46600 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56852 WEB

    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "weaviate-fips"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "1.38.6-r2"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Multiple security vulnerabilities affect the weaviate-fips package. HashiCorp memberlist before version 0. See references for individual vulnerability details.",
      "id": "CLEANSTART-2026-LJ43739",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-09-08T00:47:15.121281Z",
      "references": [
        {
          "type": "ADVISORY",
          "url": "https://github.com/cleanstart-dev/cleanstart-security-advisories/tree/main/advisories/2026/CLEANSTART-2026-LJ43739.json"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-14362"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-2303"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-25680"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-25681"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-27136"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39821"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39827"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39828"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39829"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39830"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39831"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39832"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39833"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39834"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39835"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42502"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42506"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42508"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-46595"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-46597"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-46598"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-46600"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56852"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-259r-337f-4rfw"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-cp6g-7hqx-qxhp"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-14362"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-2303"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25680"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25681"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27136"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39821"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39827"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39828"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39829"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39830"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39831"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39832"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39833"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39834"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39835"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42502"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42506"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42508"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46595"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46597"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46598"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46600"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56852"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "severity": [
        {
          "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "type": "CVSS_V3"
        }
      ],
      "summary": "HashiCorp memberlist before version 0",
      "upstream": [
        "CVE-2026-14362",
        "CVE-2026-2303",
        "CVE-2026-25680",
        "CVE-2026-25681",
        "CVE-2026-27136",
        "CVE-2026-39821",
        "CVE-2026-39827",
        "CVE-2026-39828",
        "CVE-2026-39829",
        "CVE-2026-39830",
        "CVE-2026-39831",
        "CVE-2026-39832",
        "CVE-2026-39833",
        "CVE-2026-39834",
        "CVE-2026-39835",
        "CVE-2026-42502",
        "CVE-2026-42506",
        "CVE-2026-42508",
        "CVE-2026-46595",
        "CVE-2026-46597",
        "CVE-2026-46598",
        "CVE-2026-46600",
        "CVE-2026-56852",
        "ghsa-259r-337f-4rfw",
        "ghsa-cp6g-7hqx-qxhp"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-LJ97657 (CVE-2026-25680)

    Vulnerability from cleanstart – Published: 2026-09-16 01:18 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection
    Details

    Multiple security vulnerabilities affect the cadvisor package. Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. See references for individual vulnerability details.

    References
    https://github.com/cleanstart-dev/cleanstart-secu… ADVISORY
    https://osv.dev/vulnerability/CVE-2026-25680 WEB
    https://osv.dev/vulnerability/CVE-2026-25681 WEB
    https://osv.dev/vulnerability/CVE-2026-27136 WEB
    https://osv.dev/vulnerability/CVE-2026-29181 WEB
    https://osv.dev/vulnerability/CVE-2026-33186 WEB
    https://osv.dev/vulnerability/CVE-2026-33814 WEB
    https://osv.dev/vulnerability/CVE-2026-33818 WEB
    https://osv.dev/vulnerability/CVE-2026-39821 WEB
    https://osv.dev/vulnerability/CVE-2026-39822 WEB
    https://osv.dev/vulnerability/CVE-2026-39824 WEB
    https://osv.dev/vulnerability/CVE-2026-39827 WEB
    https://osv.dev/vulnerability/CVE-2026-39828 WEB
    https://osv.dev/vulnerability/CVE-2026-39829 WEB
    https://osv.dev/vulnerability/CVE-2026-39830 WEB
    https://osv.dev/vulnerability/CVE-2026-39831 WEB
    https://osv.dev/vulnerability/CVE-2026-39832 WEB
    https://osv.dev/vulnerability/CVE-2026-39833 WEB
    https://osv.dev/vulnerability/CVE-2026-39834 WEB
    https://osv.dev/vulnerability/CVE-2026-39835 WEB
    https://osv.dev/vulnerability/CVE-2026-41178 WEB
    https://osv.dev/vulnerability/CVE-2026-41579 WEB
    https://osv.dev/vulnerability/CVE-2026-42502 WEB
    https://osv.dev/vulnerability/CVE-2026-42505 WEB
    https://osv.dev/vulnerability/CVE-2026-42506 WEB
    https://osv.dev/vulnerability/CVE-2026-42508 WEB
    https://osv.dev/vulnerability/CVE-2026-46595 WEB
    https://osv.dev/vulnerability/CVE-2026-46597 WEB
    https://osv.dev/vulnerability/CVE-2026-46598 WEB
    https://osv.dev/vulnerability/CVE-2026-46600 WEB
    https://osv.dev/vulnerability/CVE-2026-56852 WEB
    https://osv.dev/vulnerability/CVE-2026-56853 WEB
    https://osv.dev/vulnerability/CVE-2026-56854 WEB
    https://osv.dev/vulnerability/CVE-2026-56855 WEB
    https://osv.dev/vulnerability/CVE-2026-56858 WEB
    https://osv.dev/vulnerability/CVE-2026-56859 WEB
    https://osv.dev/vulnerability/CVE-2026-56860 WEB
    https://osv.dev/vulnerability/CVE-2026-56862 WEB
    https://osv.dev/vulnerability/CVE-2026-78662 WEB
    https://osv.dev/vulnerability/CVE-2026-84303 WEB
    https://osv.dev/vulnerability/CVE-2026-84304 WEB
    https://osv.dev/vulnerability/CVE-2026-84445 WEB
    https://osv.dev/vulnerability/ghsa-259r-337f-4rfw WEB
    https://osv.dev/vulnerability/ghsa-hrxh-6v49-42gf WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-25680 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-25681 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-27136 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-29181 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-33186 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-33814 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-33818 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39821 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39822 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39824 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39827 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39828 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39829 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39830 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39831 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39832 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39833 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39834 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39835 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-41178 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-41579 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42502 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42505 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42506 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42508 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-46595 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-46597 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-46598 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-46600 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56852 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56853 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56854 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56855 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56858 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56859 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56860 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56862 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-78662 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-84303 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-84304 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-84445 WEB

    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "cadvisor"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "0.55.1-r7"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Multiple security vulnerabilities affect the cadvisor package. Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. See references for individual vulnerability details.",
      "id": "CLEANSTART-2026-LJ97657",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-09-16T01:18:45.186561Z",
      "references": [
        {
          "type": "ADVISORY",
          "url": "https://github.com/cleanstart-dev/cleanstart-security-advisories/tree/main/advisories/2026/CLEANSTART-2026-LJ97657.json"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-25680"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-25681"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-27136"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-29181"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-33186"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-33814"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-33818"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39821"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39822"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39824"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39827"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39828"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39829"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39830"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39831"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39832"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39833"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39834"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39835"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-41178"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-41579"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42502"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42505"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42506"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42508"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-46595"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-46597"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-46598"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-46600"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56852"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56853"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56854"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56855"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56858"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56859"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56860"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56862"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-78662"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-84303"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-84304"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-84445"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-259r-337f-4rfw"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-hrxh-6v49-42gf"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25680"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25681"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27136"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-29181"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33186"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33814"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33818"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39821"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39822"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39824"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39827"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39828"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39829"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39830"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39831"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39832"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39833"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39834"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39835"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41178"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41579"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42502"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42505"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42506"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42508"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46595"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46597"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46598"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46600"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56852"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56853"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56854"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56855"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56858"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56859"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56860"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56862"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78662"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84303"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84304"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84445"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "severity": [
        {
          "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "type": "CVSS_V3"
        }
      ],
      "summary": "Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection",
      "upstream": [
        "CVE-2026-25680",
        "CVE-2026-25681",
        "CVE-2026-27136",
        "CVE-2026-29181",
        "CVE-2026-33186",
        "CVE-2026-33814",
        "CVE-2026-33818",
        "CVE-2026-39821",
        "CVE-2026-39822",
        "CVE-2026-39824",
        "CVE-2026-39827",
        "CVE-2026-39828",
        "CVE-2026-39829",
        "CVE-2026-39830",
        "CVE-2026-39831",
        "CVE-2026-39832",
        "CVE-2026-39833",
        "CVE-2026-39834",
        "CVE-2026-39835",
        "CVE-2026-41178",
        "CVE-2026-41579",
        "CVE-2026-42502",
        "CVE-2026-42505",
        "CVE-2026-42506",
        "CVE-2026-42508",
        "CVE-2026-46595",
        "CVE-2026-46597",
        "CVE-2026-46598",
        "CVE-2026-46600",
        "CVE-2026-56852",
        "CVE-2026-56853",
        "CVE-2026-56854",
        "CVE-2026-56855",
        "CVE-2026-56858",
        "CVE-2026-56859",
        "CVE-2026-56860",
        "CVE-2026-56862",
        "CVE-2026-78662",
        "CVE-2026-84303",
        "CVE-2026-84304",
        "CVE-2026-84445",
        "ghsa-259r-337f-4rfw",
        "ghsa-hrxh-6v49-42gf"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-LK25174 (CVE-2025-15558)

    Vulnerability from cleanstart – Published: 2026-09-08 01:16 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label
    Details

    Multiple security vulnerabilities affect the istio package. The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. See references for individual vulnerability details.

    References
    https://github.com/cleanstart-dev/cleanstart-secu… ADVISORY
    https://osv.dev/vulnerability/CVE-2025-15558 WEB
    https://osv.dev/vulnerability/CVE-2026-25680 WEB
    https://osv.dev/vulnerability/CVE-2026-25681 WEB
    https://osv.dev/vulnerability/CVE-2026-27136 WEB
    https://osv.dev/vulnerability/CVE-2026-27145 WEB
    https://osv.dev/vulnerability/CVE-2026-33186 WEB
    https://osv.dev/vulnerability/CVE-2026-33811 WEB
    https://osv.dev/vulnerability/CVE-2026-33814 WEB
    https://osv.dev/vulnerability/CVE-2026-33818 WEB
    https://osv.dev/vulnerability/CVE-2026-35469 WEB
    https://osv.dev/vulnerability/CVE-2026-39817 WEB
    https://osv.dev/vulnerability/CVE-2026-39819 WEB
    https://osv.dev/vulnerability/CVE-2026-39820 WEB
    https://osv.dev/vulnerability/CVE-2026-39821 WEB
    https://osv.dev/vulnerability/CVE-2026-39823 WEB
    https://osv.dev/vulnerability/CVE-2026-39824 WEB
    https://osv.dev/vulnerability/CVE-2026-39825 WEB
    https://osv.dev/vulnerability/CVE-2026-39826 WEB
    https://osv.dev/vulnerability/CVE-2026-39827 WEB
    https://osv.dev/vulnerability/CVE-2026-39828 WEB
    https://osv.dev/vulnerability/CVE-2026-39829 WEB
    https://osv.dev/vulnerability/CVE-2026-39830 WEB
    https://osv.dev/vulnerability/CVE-2026-39831 WEB
    https://osv.dev/vulnerability/CVE-2026-39832 WEB
    https://osv.dev/vulnerability/CVE-2026-39833 WEB
    https://osv.dev/vulnerability/CVE-2026-39834 WEB
    https://osv.dev/vulnerability/CVE-2026-39835 WEB
    https://osv.dev/vulnerability/CVE-2026-39836 WEB
    https://osv.dev/vulnerability/CVE-2026-40179 WEB
    https://osv.dev/vulnerability/CVE-2026-42151 WEB
    https://osv.dev/vulnerability/CVE-2026-42154 WEB
    https://osv.dev/vulnerability/CVE-2026-42499 WEB
    https://osv.dev/vulnerability/CVE-2026-42501 WEB
    https://osv.dev/vulnerability/CVE-2026-42502 WEB
    https://osv.dev/vulnerability/CVE-2026-42504 WEB
    https://osv.dev/vulnerability/CVE-2026-42506 WEB
    https://osv.dev/vulnerability/CVE-2026-42507 WEB
    https://osv.dev/vulnerability/CVE-2026-42508 WEB
    https://osv.dev/vulnerability/CVE-2026-44903 WEB
    https://osv.dev/vulnerability/CVE-2026-46595 WEB
    https://osv.dev/vulnerability/CVE-2026-46597 WEB
    https://osv.dev/vulnerability/CVE-2026-46598 WEB
    https://osv.dev/vulnerability/CVE-2026-46600 WEB
    https://osv.dev/vulnerability/CVE-2026-56852 WEB
    https://osv.dev/vulnerability/CVE-2026-56853 WEB
    https://osv.dev/vulnerability/CVE-2026-56858 WEB
    https://osv.dev/vulnerability/CVE-2026-56859 WEB
    https://osv.dev/vulnerability/CVE-2026-56860 WEB
    https://osv.dev/vulnerability/CVE-2026-56862 WEB
    https://osv.dev/vulnerability/ghsa-259r-337f-4rfw WEB
    https://osv.dev/vulnerability/ghsa-8rm2-7qqf-34qm WEB
    https://osv.dev/vulnerability/ghsa-fw8g-cg8f-9j28 WEB
    https://osv.dev/vulnerability/ghsa-gcjh-h69q-9w9g WEB
    https://osv.dev/vulnerability/ghsa-hrxh-6v49-42gf WEB
    https://osv.dev/vulnerability/ghsa-p436-gjf2-799p WEB
    https://osv.dev/vulnerability/ghsa-p77j-4mvh-x3m3 WEB
    https://osv.dev/vulnerability/ghsa-vffh-x6r8-xx99 WEB
    https://osv.dev/vulnerability/ghsa-wg65-39gg-5wfj WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-15558 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-25680 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-25681 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-27136 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-27145 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-33186 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-33811 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-33814 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-33818 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-35469 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39817 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39819 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39820 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39821 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39823 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39824 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39825 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39826 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39827 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39828 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39829 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39830 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39831 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39832 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39833 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39834 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39835 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39836 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-40179 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42151 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42154 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42499 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42501 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42502 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42504 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42506 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42507 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42508 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-44903 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-46595 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-46597 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-46598 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-46600 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56852 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56853 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56858 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56859 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56860 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56862 WEB

    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "istio"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "1.29.6-r2"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Multiple security vulnerabilities affect the istio package. The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. See references for individual vulnerability details.",
      "id": "CLEANSTART-2026-LK25174",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-09-08T01:16:17.892966Z",
      "references": [
        {
          "type": "ADVISORY",
          "url": "https://github.com/cleanstart-dev/cleanstart-security-advisories/tree/main/advisories/2026/CLEANSTART-2026-LK25174.json"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-15558"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-25680"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-25681"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-27136"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-27145"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-33186"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-33811"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-33814"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-33818"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-35469"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39817"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39819"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39820"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39821"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39823"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39824"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39825"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39826"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39827"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39828"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39829"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39830"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39831"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39832"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39833"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39834"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39835"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39836"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-40179"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42151"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42154"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42499"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42501"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42502"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42504"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42506"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42507"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42508"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-44903"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-46595"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-46597"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-46598"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-46600"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56852"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56853"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56858"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56859"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56860"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56862"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-259r-337f-4rfw"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-8rm2-7qqf-34qm"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-fw8g-cg8f-9j28"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-gcjh-h69q-9w9g"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-hrxh-6v49-42gf"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-p436-gjf2-799p"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-p77j-4mvh-x3m3"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-vffh-x6r8-xx99"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-wg65-39gg-5wfj"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-15558"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25680"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25681"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27136"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27145"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33186"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33811"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33814"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33818"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-35469"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39817"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39819"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39820"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39821"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39823"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39824"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39825"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39826"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39827"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39828"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39829"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39830"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39831"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39832"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39833"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39834"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39835"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39836"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-40179"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42151"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42154"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42499"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42501"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42502"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42504"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42506"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42507"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42508"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-44903"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46595"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46597"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46598"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46600"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56852"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56853"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56858"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56859"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56860"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56862"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "severity": [
        {
          "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "type": "CVSS_V3"
        }
      ],
      "summary": "ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label",
      "upstream": [
        "CVE-2025-15558",
        "CVE-2026-25680",
        "CVE-2026-25681",
        "CVE-2026-27136",
        "CVE-2026-27145",
        "CVE-2026-33186",
        "CVE-2026-33811",
        "CVE-2026-33814",
        "CVE-2026-33818",
        "CVE-2026-35469",
        "CVE-2026-39817",
        "CVE-2026-39819",
        "CVE-2026-39820",
        "CVE-2026-39821",
        "CVE-2026-39823",
        "CVE-2026-39824",
        "CVE-2026-39825",
        "CVE-2026-39826",
        "CVE-2026-39827",
        "CVE-2026-39828",
        "CVE-2026-39829",
        "CVE-2026-39830",
        "CVE-2026-39831",
        "CVE-2026-39832",
        "CVE-2026-39833",
        "CVE-2026-39834",
        "CVE-2026-39835",
        "CVE-2026-39836",
        "CVE-2026-40179",
        "CVE-2026-42151",
        "CVE-2026-42154",
        "CVE-2026-42499",
        "CVE-2026-42501",
        "CVE-2026-42502",
        "CVE-2026-42504",
        "CVE-2026-42506",
        "CVE-2026-42507",
        "CVE-2026-42508",
        "CVE-2026-44903",
        "CVE-2026-46595",
        "CVE-2026-46597",
        "CVE-2026-46598",
        "CVE-2026-46600",
        "CVE-2026-56852",
        "CVE-2026-56853",
        "CVE-2026-56858",
        "CVE-2026-56859",
        "CVE-2026-56860",
        "CVE-2026-56862",
        "ghsa-259r-337f-4rfw",
        "ghsa-8rm2-7qqf-34qm",
        "ghsa-fw8g-cg8f-9j28",
        "ghsa-gcjh-h69q-9w9g",
        "ghsa-hrxh-6v49-42gf",
        "ghsa-p436-gjf2-799p",
        "ghsa-p77j-4mvh-x3m3",
        "ghsa-vffh-x6r8-xx99",
        "ghsa-wg65-39gg-5wfj"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-LM38080 (GHSA-259R-337F-4RFW)

    Vulnerability from cleanstart – Published: 2026-08-13 12:10 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    Security fixes in elastic-beats 9.3.9-r0
    Details

    Package elastic-beats version 9.3.9-r0 fixes 1 vulnerabilities: ghsa-259r-337f-4rfw

    References

    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "elastic-beats"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "9.3.9-r0"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "9.3.9-r0"
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Package elastic-beats version 9.3.9-r0 fixes 1 vulnerabilities: ghsa-259r-337f-4rfw",
      "id": "CLEANSTART-2026-LM38080",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-08-13T12:10:09Z",
      "references": [
        {
          "type": "WEB",
          "url": "https://www.elastic.co/products/beats"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "summary": "Security fixes in elastic-beats 9.3.9-r0",
      "upstream": [
        "ghsa-259r-337f-4rfw"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-LQ54152 (CVE-2026-33818)

    Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    Security fixes in ollama-fips 0.32.11-r1
    Details

    Package ollama-fips version 0.32.11-r1 fixes 11 vulnerabilities: CVE-2026-33818, CVE-2026-56853, CVE-2026-56858, CVE-2026-56859, CVE-2026-56860...

    References

    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "ollama-fips"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "0.32.11-r1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "0.32.11-r1"
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Package ollama-fips version 0.32.11-r1 fixes 11 vulnerabilities: CVE-2026-33818, CVE-2026-56853, CVE-2026-56858, CVE-2026-56859, CVE-2026-56860...",
      "id": "CLEANSTART-2026-LQ54152",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-09-01T11:17:16Z",
      "references": [
        {
          "type": "WEB",
          "url": "https://ollama.com"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "summary": "Security fixes in ollama-fips 0.32.11-r1",
      "upstream": [
        "CVE-2026-33818",
        "CVE-2026-56853",
        "CVE-2026-56858",
        "CVE-2026-56859",
        "CVE-2026-56860",
        "CVE-2026-56862",
        "CVE-2026-46600",
        "CVE-2026-39821",
        "CVE-2026-56864",
        "CVE-2026-56865",
        "ghsa-259r-337f-4rfw"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-ME39024 (CVE-2026-5724)

    Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    Security fixes in temporal-server 1.29.7-r2
    Details

    Package temporal-server version 1.29.7-r2 fixes 7 vulnerabilities: CVE-2026-5724, CVE-2025-14987, CVE-2025-14986, CVE-2026-5199, ghsa-hrxh-6v49-42gf...

    References

    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "temporal-server"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "1.29.7-r2"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "1.29.7-r2"
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Package temporal-server version 1.29.7-r2 fixes 7 vulnerabilities: CVE-2026-5724, CVE-2025-14987, CVE-2025-14986, CVE-2026-5199, ghsa-hrxh-6v49-42gf...",
      "id": "CLEANSTART-2026-ME39024",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-09-01T11:17:16Z",
      "references": [
        {
          "type": "WEB",
          "url": "https://github.com/temporalio/temporal"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "summary": "Security fixes in temporal-server 1.29.7-r2",
      "upstream": [
        "CVE-2026-5724",
        "CVE-2025-14987",
        "CVE-2025-14986",
        "CVE-2026-5199",
        "ghsa-hrxh-6v49-42gf",
        "CVE-2026-41178",
        "ghsa-259r-337f-4rfw"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-MW79791 (GHSA-HRXH-6V49-42GF)

    Vulnerability from cleanstart – Published: 2026-08-13 12:10 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    Security fixes in prometheus 3.13.1-r2
    Details

    Package prometheus version 3.13.1-r2 fixes 2 vulnerabilities: ghsa-hrxh-6v49-42gf, ghsa-259r-337f-4rfw


    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "prometheus"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "3.13.1-r2"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "3.13.1-r2"
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Package prometheus version 3.13.1-r2 fixes 2 vulnerabilities: ghsa-hrxh-6v49-42gf, ghsa-259r-337f-4rfw",
      "id": "CLEANSTART-2026-MW79791",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-08-13T12:10:09Z",
      "references": [
        {
          "type": "WEB",
          "url": "https://github.com/prometheus/prometheus"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "summary": "Security fixes in prometheus 3.13.1-r2",
      "upstream": [
        "ghsa-hrxh-6v49-42gf",
        "ghsa-259r-337f-4rfw"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-NJ73427 (CVE-2026-39821)

    Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    Security fixes in tekton-chains-fips 0.25.2-r1
    Details

    Package tekton-chains-fips version 0.25.2-r1 fixes 31 vulnerabilities: CVE-2026-39821, CVE-2026-33818, CVE-2026-46600, CVE-2026-56853, CVE-2026-56858...

    References

    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "tekton-chains-fips"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "0.25.2-r1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "0.25.2-r1"
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Package tekton-chains-fips version 0.25.2-r1 fixes 31 vulnerabilities: CVE-2026-39821, CVE-2026-33818, CVE-2026-46600, CVE-2026-56853, CVE-2026-56858...",
      "id": "CLEANSTART-2026-NJ73427",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-09-01T11:17:16Z",
      "references": [
        {
          "type": "WEB",
          "url": "https://github.com/tektoncd/chains"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "summary": "Security fixes in tekton-chains-fips 0.25.2-r1",
      "upstream": [
        "CVE-2026-39821",
        "CVE-2026-33818",
        "CVE-2026-46600",
        "CVE-2026-56853",
        "CVE-2026-56858",
        "CVE-2026-56859",
        "CVE-2026-56860",
        "CVE-2026-56862",
        "ghsa-gcjh-h69q-9w9g",
        "ghsa-pmwq-pjrm-6p5r",
        "CVE-2026-49478",
        "CVE-2026-48702",
        "CVE-2026-54787",
        "CVE-2026-49834",
        "CVE-2026-49835",
        "CVE-2026-39984",
        "CVE-2026-40161",
        "CVE-2026-40938",
        "CVE-2026-25542",
        "CVE-2026-40923",
        "CVE-2026-40924",
        "CVE-2026-2303",
        "CVE-2026-39883",
        "ghsa-hrxh-6v49-42gf",
        "CVE-2026-56865",
        "CVE-2026-56864",
        "ghsa-259r-337f-4rfw",
        "ghsa-rjr7-jggh-pgcp",
        "ghsa-3fxj-6jh8-hvhx",
        "ghsa-9g5q-2w5x-hmxf",
        "CVE-2026-41178"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-NN12099 (CVE-2025-61732)

    Vulnerability from cleanstart – Published: 2026-09-11 00:52 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection
    Details

    Multiple security vulnerabilities affect the haproxy-ingress package. Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. See references for individual vulnerability details.

    References
    https://github.com/cleanstart-dev/cleanstart-secu… ADVISORY
    https://osv.dev/vulnerability/CVE-2025-61732 WEB
    https://osv.dev/vulnerability/CVE-2025-68121 WEB
    https://osv.dev/vulnerability/CVE-2026-25679 WEB
    https://osv.dev/vulnerability/CVE-2026-25680 WEB
    https://osv.dev/vulnerability/CVE-2026-25681 WEB
    https://osv.dev/vulnerability/CVE-2026-27136 WEB
    https://osv.dev/vulnerability/CVE-2026-27139 WEB
    https://osv.dev/vulnerability/CVE-2026-27142 WEB
    https://osv.dev/vulnerability/CVE-2026-33814 WEB
    https://osv.dev/vulnerability/CVE-2026-33818 WEB
    https://osv.dev/vulnerability/CVE-2026-39821 WEB
    https://osv.dev/vulnerability/CVE-2026-39824 WEB
    https://osv.dev/vulnerability/CVE-2026-39827 WEB
    https://osv.dev/vulnerability/CVE-2026-39828 WEB
    https://osv.dev/vulnerability/CVE-2026-39829 WEB
    https://osv.dev/vulnerability/CVE-2026-39830 WEB
    https://osv.dev/vulnerability/CVE-2026-39831 WEB
    https://osv.dev/vulnerability/CVE-2026-39832 WEB
    https://osv.dev/vulnerability/CVE-2026-39833 WEB
    https://osv.dev/vulnerability/CVE-2026-39834 WEB
    https://osv.dev/vulnerability/CVE-2026-39835 WEB
    https://osv.dev/vulnerability/CVE-2026-42502 WEB
    https://osv.dev/vulnerability/CVE-2026-42506 WEB
    https://osv.dev/vulnerability/CVE-2026-42508 WEB
    https://osv.dev/vulnerability/CVE-2026-46595 WEB
    https://osv.dev/vulnerability/CVE-2026-46597 WEB
    https://osv.dev/vulnerability/CVE-2026-46598 WEB
    https://osv.dev/vulnerability/CVE-2026-46600 WEB
    https://osv.dev/vulnerability/CVE-2026-56852 WEB
    https://osv.dev/vulnerability/CVE-2026-56853 WEB
    https://osv.dev/vulnerability/CVE-2026-56854 WEB
    https://osv.dev/vulnerability/CVE-2026-56855 WEB
    https://osv.dev/vulnerability/CVE-2026-56858 WEB
    https://osv.dev/vulnerability/CVE-2026-56859 WEB
    https://osv.dev/vulnerability/CVE-2026-56860 WEB
    https://osv.dev/vulnerability/CVE-2026-56862 WEB
    https://osv.dev/vulnerability/CVE-2026-78662 WEB
    https://osv.dev/vulnerability/ghsa-259r-337f-4rfw WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-61732 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-68121 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-25679 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-25680 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-25681 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-27136 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-27139 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-27142 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-33814 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-33818 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39821 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39824 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39827 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39828 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39829 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39830 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39831 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39832 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39833 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39834 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39835 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42502 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42506 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42508 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-46595 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-46597 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-46598 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-46600 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56852 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56853 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56854 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56855 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56858 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56859 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56860 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56862 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-78662 WEB

    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "haproxy-ingress"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "0.15.1-r0"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Multiple security vulnerabilities affect the haproxy-ingress package. Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. See references for individual vulnerability details.",
      "id": "CLEANSTART-2026-NN12099",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-09-11T00:52:10.418800Z",
      "references": [
        {
          "type": "ADVISORY",
          "url": "https://github.com/cleanstart-dev/cleanstart-security-advisories/tree/main/advisories/2026/CLEANSTART-2026-NN12099.json"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-61732"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-68121"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-25679"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-25680"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-25681"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-27136"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-27139"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-27142"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-33814"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-33818"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39821"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39824"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39827"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39828"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39829"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39830"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39831"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39832"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39833"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39834"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39835"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42502"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42506"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42508"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-46595"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-46597"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-46598"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-46600"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56852"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56853"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56854"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56855"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56858"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56859"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56860"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56862"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-78662"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-259r-337f-4rfw"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61732"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-68121"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25679"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25680"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25681"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27136"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27139"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27142"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33814"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33818"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39821"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39824"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39827"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39828"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39829"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39830"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39831"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39832"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39833"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39834"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39835"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42502"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42506"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42508"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46595"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46597"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46598"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46600"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56852"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56853"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56854"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56855"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56858"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56859"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56860"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56862"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78662"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "severity": [
        {
          "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "type": "CVSS_V3"
        }
      ],
      "summary": "Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection",
      "upstream": [
        "CVE-2025-61732",
        "CVE-2025-68121",
        "CVE-2026-25679",
        "CVE-2026-25680",
        "CVE-2026-25681",
        "CVE-2026-27136",
        "CVE-2026-27139",
        "CVE-2026-27142",
        "CVE-2026-33814",
        "CVE-2026-33818",
        "CVE-2026-39821",
        "CVE-2026-39824",
        "CVE-2026-39827",
        "CVE-2026-39828",
        "CVE-2026-39829",
        "CVE-2026-39830",
        "CVE-2026-39831",
        "CVE-2026-39832",
        "CVE-2026-39833",
        "CVE-2026-39834",
        "CVE-2026-39835",
        "CVE-2026-42502",
        "CVE-2026-42506",
        "CVE-2026-42508",
        "CVE-2026-46595",
        "CVE-2026-46597",
        "CVE-2026-46598",
        "CVE-2026-46600",
        "CVE-2026-56852",
        "CVE-2026-56853",
        "CVE-2026-56854",
        "CVE-2026-56855",
        "CVE-2026-56858",
        "CVE-2026-56859",
        "CVE-2026-56860",
        "CVE-2026-56862",
        "CVE-2026-78662",
        "ghsa-259r-337f-4rfw"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-NO03449 (GHSA-259R-337F-4RFW)

    Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    Security fixes in ollama-fips 0.32.9-r2
    Details

    Package ollama-fips version 0.32.9-r2 fixes 1 vulnerabilities: ghsa-259r-337f-4rfw

    References

    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "ollama-fips"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "0.32.9-r2"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "0.32.9-r2"
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Package ollama-fips version 0.32.9-r2 fixes 1 vulnerabilities: ghsa-259r-337f-4rfw",
      "id": "CLEANSTART-2026-NO03449",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-09-01T11:17:16Z",
      "references": [
        {
          "type": "WEB",
          "url": "https://ollama.com"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "summary": "Security fixes in ollama-fips 0.32.9-r2",
      "upstream": [
        "ghsa-259r-337f-4rfw"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-NR19543 (GHSA-HRXH-6V49-42GF)

    Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    Security fixes in prometheus-fips 3.10.0-r1
    Details

    Package prometheus-fips version 3.10.0-r1 fixes 3 vulnerabilities: ghsa-hrxh-6v49-42gf, CVE-2026-2303, ghsa-259r-337f-4rfw


    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "prometheus-fips"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "3.10.0-r1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "3.10.0-r1"
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Package prometheus-fips version 3.10.0-r1 fixes 3 vulnerabilities: ghsa-hrxh-6v49-42gf, CVE-2026-2303, ghsa-259r-337f-4rfw",
      "id": "CLEANSTART-2026-NR19543",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-09-01T11:17:16Z",
      "references": [
        {
          "type": "WEB",
          "url": "https://github.com/prometheus/prometheus"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "summary": "Security fixes in prometheus-fips 3.10.0-r1",
      "upstream": [
        "ghsa-hrxh-6v49-42gf",
        "CVE-2026-2303",
        "ghsa-259r-337f-4rfw"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-NY04600 (GHSA-259R-337F-4RFW)

    Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    Security fixes in argo-cd 3.3.14-r2
    Details

    Package argo-cd version 3.3.14-r2 fixes 1 vulnerabilities: ghsa-259r-337f-4rfw

    References

    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "argo-cd"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "3.3.14-r2"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "3.3.14-r2"
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Package argo-cd version 3.3.14-r2 fixes 1 vulnerabilities: ghsa-259r-337f-4rfw",
      "id": "CLEANSTART-2026-NY04600",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-09-01T11:17:16Z",
      "references": [
        {
          "type": "WEB",
          "url": "https://github.com/argoproj/argo-cd"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "summary": "Security fixes in argo-cd 3.3.14-r2",
      "upstream": [
        "ghsa-259r-337f-4rfw"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-NZ51335 (CVE-2026-33818)

    Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    Security fixes in tekton-chains-fips 0.26.5-r1
    Details

    Package tekton-chains-fips version 0.26.5-r1 fixes 25 vulnerabilities: CVE-2026-33818, CVE-2026-46600, CVE-2026-56853, CVE-2026-56858, CVE-2026-56859...

    References

    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "tekton-chains-fips"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "0.26.5-r1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "0.26.5-r1"
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Package tekton-chains-fips version 0.26.5-r1 fixes 25 vulnerabilities: CVE-2026-33818, CVE-2026-46600, CVE-2026-56853, CVE-2026-56858, CVE-2026-56859...",
      "id": "CLEANSTART-2026-NZ51335",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-09-01T11:17:16Z",
      "references": [
        {
          "type": "WEB",
          "url": "https://github.com/tektoncd/chains"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "summary": "Security fixes in tekton-chains-fips 0.26.5-r1",
      "upstream": [
        "CVE-2026-33818",
        "CVE-2026-46600",
        "CVE-2026-56853",
        "CVE-2026-56858",
        "CVE-2026-56859",
        "CVE-2026-56860",
        "CVE-2026-56862",
        "CVE-2026-39821",
        "ghsa-gcjh-h69q-9w9g",
        "CVE-2026-49478",
        "CVE-2026-48702",
        "CVE-2026-54787",
        "CVE-2026-49834",
        "CVE-2026-49835",
        "CVE-2026-39984",
        "CVE-2026-2303",
        "CVE-2026-39883",
        "ghsa-hrxh-6v49-42gf",
        "CVE-2026-56864",
        "CVE-2026-56865",
        "ghsa-259r-337f-4rfw",
        "ghsa-3fxj-6jh8-hvhx",
        "ghsa-9g5q-2w5x-hmxf",
        "ghsa-rjr7-jggh-pgcp",
        "CVE-2026-41178"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-OO93790 (GHSA-HRXH-6V49-42GF)

    Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    Security fixes in argo-cd 3.4.6-r0
    Details

    Package argo-cd version 3.4.6-r0 fixes 3 vulnerabilities: ghsa-hrxh-6v49-42gf, ghsa-259r-337f-4rfw, CVE-2026-41178

    References

    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "argo-cd"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "3.4.6-r0"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "3.4.6-r0"
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Package argo-cd version 3.4.6-r0 fixes 3 vulnerabilities: ghsa-hrxh-6v49-42gf, ghsa-259r-337f-4rfw, CVE-2026-41178",
      "id": "CLEANSTART-2026-OO93790",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-09-01T11:17:16Z",
      "references": [
        {
          "type": "WEB",
          "url": "https://github.com/argoproj/argo-cd"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "summary": "Security fixes in argo-cd 3.4.6-r0",
      "upstream": [
        "ghsa-hrxh-6v49-42gf",
        "ghsa-259r-337f-4rfw",
        "CVE-2026-41178"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-OO99794 (CVE-2026-56860)

    Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    Security fixes in argo-cd-fips 3.4.7-r1
    Details

    Package argo-cd-fips version 3.4.7-r1 fixes 13 vulnerabilities: CVE-2026-56860, CVE-2026-56858, CVE-2026-33818, CVE-2026-56853, CVE-2026-56859...

    References

    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "argo-cd-fips"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "3.4.7-r1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "3.4.7-r1"
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Package argo-cd-fips version 3.4.7-r1 fixes 13 vulnerabilities: CVE-2026-56860, CVE-2026-56858, CVE-2026-33818, CVE-2026-56853, CVE-2026-56859...",
      "id": "CLEANSTART-2026-OO99794",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-09-01T11:17:16Z",
      "references": [
        {
          "type": "WEB",
          "url": "https://github.com/argoproj/argo-cd"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "summary": "Security fixes in argo-cd-fips 3.4.7-r1",
      "upstream": [
        "CVE-2026-56860",
        "CVE-2026-56858",
        "CVE-2026-33818",
        "CVE-2026-56853",
        "CVE-2026-56859",
        "CVE-2026-56862",
        "CVE-2026-39821",
        "CVE-2026-46600",
        "CVE-2026-50163",
        "CVE-2026-71556",
        "CVE-2026-71557",
        "ghsa-259r-337f-4rfw",
        "CVE-2026-56852"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-OS02559 (CVE-2026-50195)

    Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    Security fixes in rancher-fleet-agent 0.16.1-r1
    Details

    Package rancher-fleet-agent version 0.16.1-r1 fixes 40 vulnerabilities: CVE-2026-50195, CVE-2026-53492, CVE-2026-46680, CVE-2026-53488, CVE-2026-53489...

    References

    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "rancher-fleet-agent"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "0.16.1-r1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "0.16.1-r1"
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Package rancher-fleet-agent version 0.16.1-r1 fixes 40 vulnerabilities: CVE-2026-50195, CVE-2026-53492, CVE-2026-46680, CVE-2026-53488, CVE-2026-53489...",
      "id": "CLEANSTART-2026-OS02559",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-09-01T11:17:16Z",
      "references": [
        {
          "type": "WEB",
          "url": "https://github.com/rancher/fleet"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "summary": "Security fixes in rancher-fleet-agent 0.16.1-r1",
      "upstream": [
        "CVE-2026-50195",
        "CVE-2026-53492",
        "CVE-2026-46680",
        "CVE-2026-53488",
        "CVE-2026-53489",
        "CVE-2026-47262",
        "CVE-2026-42508",
        "CVE-2026-39835",
        "CVE-2026-46598",
        "CVE-2026-39828",
        "CVE-2026-39829",
        "CVE-2026-46597",
        "CVE-2026-39830",
        "CVE-2026-39831",
        "CVE-2026-39832",
        "CVE-2026-39833",
        "CVE-2026-39834",
        "CVE-2026-46595",
        "CVE-2026-39827",
        "CVE-2026-33186",
        "ghsa-hrxh-6v49-42gf",
        "CVE-2026-25681",
        "CVE-2026-27136",
        "CVE-2026-33814",
        "CVE-2026-46600",
        "CVE-2026-39821",
        "CVE-2026-42502",
        "CVE-2026-42506",
        "CVE-2026-25680",
        "CVE-2026-29181",
        "CVE-2026-35469",
        "CVE-2026-56852",
        "CVE-2026-48978",
        "CVE-2026-50163",
        "CVE-2026-50151",
        "CVE-2026-50162",
        "ghsa-vh4v-2xq2-g5cg",
        "CVE-2026-39824",
        "CVE-2026-35206",
        "ghsa-259r-337f-4rfw"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-PB67247 (CVE-2026-56860)

    Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    Security fixes in temporal-server 1.30.6-r2
    Details

    Package temporal-server version 1.30.6-r2 fixes 11 vulnerabilities: CVE-2026-56860, CVE-2026-56858, CVE-2026-33818, CVE-2026-46600, CVE-2026-56853...

    References

    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "temporal-server"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "1.30.6-r2"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "1.30.6-r2"
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Package temporal-server version 1.30.6-r2 fixes 11 vulnerabilities: CVE-2026-56860, CVE-2026-56858, CVE-2026-33818, CVE-2026-46600, CVE-2026-56853...",
      "id": "CLEANSTART-2026-PB67247",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-09-01T11:17:16Z",
      "references": [
        {
          "type": "WEB",
          "url": "https://github.com/temporalio/temporal"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "summary": "Security fixes in temporal-server 1.30.6-r2",
      "upstream": [
        "CVE-2026-56860",
        "CVE-2026-56858",
        "CVE-2026-33818",
        "CVE-2026-46600",
        "CVE-2026-56853",
        "CVE-2026-56859",
        "CVE-2026-56862",
        "CVE-2026-39821",
        "ghsa-hrxh-6v49-42gf",
        "CVE-2026-41178",
        "ghsa-259r-337f-4rfw"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-PC33523 (CVE-2026-2303)

    Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    Security fixes in karma 0.128-r1
    Details

    Package karma version 0.128-r1 fixes 6 vulnerabilities: CVE-2026-2303, CVE-2026-39824, ghsa-259r-337f-4rfw, ghsa-3fxj-6jh8-hvhx, ghsa-9g5q-2w5x-hmxf...

    References

    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "karma"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "0.128-r1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "0.128-r1"
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Package karma version 0.128-r1 fixes 6 vulnerabilities: CVE-2026-2303, CVE-2026-39824, ghsa-259r-337f-4rfw, ghsa-3fxj-6jh8-hvhx, ghsa-9g5q-2w5x-hmxf...",
      "id": "CLEANSTART-2026-PC33523",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-09-01T11:17:16Z",
      "references": [
        {
          "type": "WEB",
          "url": "https://github.com/prymitive/karma.git"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "summary": "Security fixes in karma 0.128-r1",
      "upstream": [
        "CVE-2026-2303",
        "CVE-2026-39824",
        "ghsa-259r-337f-4rfw",
        "ghsa-3fxj-6jh8-hvhx",
        "ghsa-9g5q-2w5x-hmxf",
        "ghsa-rjr7-jggh-pgcp"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-PE88816 (CVE-2025-47912)

    Vulnerability from cleanstart – Published: 2026-09-08 01:30 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label
    Details

    Multiple security vulnerabilities affect the helm-operator package. The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. See references for individual vulnerability details.

    References
    https://github.com/cleanstart-dev/cleanstart-secu… ADVISORY
    https://osv.dev/vulnerability/CVE-2025-47912 WEB
    https://osv.dev/vulnerability/CVE-2025-58183 WEB
    https://osv.dev/vulnerability/CVE-2025-58185 WEB
    https://osv.dev/vulnerability/CVE-2025-58186 WEB
    https://osv.dev/vulnerability/CVE-2025-58187 WEB
    https://osv.dev/vulnerability/CVE-2025-58188 WEB
    https://osv.dev/vulnerability/CVE-2025-58189 WEB
    https://osv.dev/vulnerability/CVE-2025-61723 WEB
    https://osv.dev/vulnerability/CVE-2025-61724 WEB
    https://osv.dev/vulnerability/CVE-2025-61725 WEB
    https://osv.dev/vulnerability/CVE-2025-61729 WEB
    https://osv.dev/vulnerability/CVE-2026-25680 WEB
    https://osv.dev/vulnerability/CVE-2026-25681 WEB
    https://osv.dev/vulnerability/CVE-2026-27136 WEB
    https://osv.dev/vulnerability/CVE-2026-27140 WEB
    https://osv.dev/vulnerability/CVE-2026-27143 WEB
    https://osv.dev/vulnerability/CVE-2026-27144 WEB
    https://osv.dev/vulnerability/CVE-2026-27145 WEB
    https://osv.dev/vulnerability/CVE-2026-29181 WEB
    https://osv.dev/vulnerability/CVE-2026-32280 WEB
    https://osv.dev/vulnerability/CVE-2026-32281 WEB
    https://osv.dev/vulnerability/CVE-2026-32282 WEB
    https://osv.dev/vulnerability/CVE-2026-32283 WEB
    https://osv.dev/vulnerability/CVE-2026-32288 WEB
    https://osv.dev/vulnerability/CVE-2026-32289 WEB
    https://osv.dev/vulnerability/CVE-2026-33811 WEB
    https://osv.dev/vulnerability/CVE-2026-33814 WEB
    https://osv.dev/vulnerability/CVE-2026-33818 WEB
    https://osv.dev/vulnerability/CVE-2026-35206 WEB
    https://osv.dev/vulnerability/CVE-2026-35469 WEB
    https://osv.dev/vulnerability/CVE-2026-39817 WEB
    https://osv.dev/vulnerability/CVE-2026-39819 WEB
    https://osv.dev/vulnerability/CVE-2026-39820 WEB
    https://osv.dev/vulnerability/CVE-2026-39821 WEB
    https://osv.dev/vulnerability/CVE-2026-39823 WEB
    https://osv.dev/vulnerability/CVE-2026-39824 WEB
    https://osv.dev/vulnerability/CVE-2026-39825 WEB
    https://osv.dev/vulnerability/CVE-2026-39826 WEB
    https://osv.dev/vulnerability/CVE-2026-39827 WEB
    https://osv.dev/vulnerability/CVE-2026-39828 WEB
    https://osv.dev/vulnerability/CVE-2026-39829 WEB
    https://osv.dev/vulnerability/CVE-2026-39830 WEB
    https://osv.dev/vulnerability/CVE-2026-39831 WEB
    https://osv.dev/vulnerability/CVE-2026-39832 WEB
    https://osv.dev/vulnerability/CVE-2026-39833 WEB
    https://osv.dev/vulnerability/CVE-2026-39834 WEB
    https://osv.dev/vulnerability/CVE-2026-39835 WEB
    https://osv.dev/vulnerability/CVE-2026-39836 WEB
    https://osv.dev/vulnerability/CVE-2026-39883 WEB
    https://osv.dev/vulnerability/CVE-2026-41178 WEB
    https://osv.dev/vulnerability/CVE-2026-42499 WEB
    https://osv.dev/vulnerability/CVE-2026-42501 WEB
    https://osv.dev/vulnerability/CVE-2026-42502 WEB
    https://osv.dev/vulnerability/CVE-2026-42504 WEB
    https://osv.dev/vulnerability/CVE-2026-42506 WEB
    https://osv.dev/vulnerability/CVE-2026-42507 WEB
    https://osv.dev/vulnerability/CVE-2026-42508 WEB
    https://osv.dev/vulnerability/CVE-2026-46595 WEB
    https://osv.dev/vulnerability/CVE-2026-46597 WEB
    https://osv.dev/vulnerability/CVE-2026-46598 WEB
    https://osv.dev/vulnerability/CVE-2026-46600 WEB
    https://osv.dev/vulnerability/CVE-2026-46680 WEB
    https://osv.dev/vulnerability/CVE-2026-47262 WEB
    https://osv.dev/vulnerability/CVE-2026-50163 WEB
    https://osv.dev/vulnerability/CVE-2026-53488 WEB
    https://osv.dev/vulnerability/CVE-2026-56853 WEB
    https://osv.dev/vulnerability/CVE-2026-56858 WEB
    https://osv.dev/vulnerability/CVE-2026-56859 WEB
    https://osv.dev/vulnerability/CVE-2026-56860 WEB
    https://osv.dev/vulnerability/CVE-2026-56862 WEB
    https://osv.dev/vulnerability/ghsa-259r-337f-4rfw WEB
    https://osv.dev/vulnerability/ghsa-fqw6-gf59-qr4w WEB
    https://osv.dev/vulnerability/ghsa-gcjh-h69q-9w9g WEB
    https://osv.dev/vulnerability/ghsa-hfvc-g4fc-pqhx WEB
    https://osv.dev/vulnerability/ghsa-hr2v-4r36-88hr WEB
    https://osv.dev/vulnerability/ghsa-hrxh-6v49-42gf WEB
    https://osv.dev/vulnerability/ghsa-jpcc-p29g-p8mq WEB
    https://osv.dev/vulnerability/ghsa-mh2q-q3fh-2475 WEB
    https://osv.dev/vulnerability/ghsa-pc3f-x583-g7j2 WEB
    https://osv.dev/vulnerability/ghsa-xhf5-7wjv-pqxp WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-47912 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-58183 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-58185 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-58186 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-58187 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-58188 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-58189 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-61723 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-61724 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-61725 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-61729 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-25680 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-25681 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-27136 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-27140 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-27143 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-27144 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-27145 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-29181 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-32280 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-32281 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-32282 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-32283 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-32288 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-32289 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-33811 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-33814 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-33818 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-35206 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-35469 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39817 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39819 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39820 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39821 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39823 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39824 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39825 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39826 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39827 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39828 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39829 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39830 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39831 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39832 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39833 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39834 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39835 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39836 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39883 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-41178 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42499 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42501 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42502 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42504 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42506 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42507 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42508 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-46595 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-46597 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-46598 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-46600 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-46680 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-47262 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-50163 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-53488 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56853 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56858 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56859 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56860 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56862 WEB

    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "helm-operator"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "1.42.2-r2"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Multiple security vulnerabilities affect the helm-operator package. The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. See references for individual vulnerability details.",
      "id": "CLEANSTART-2026-PE88816",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-09-08T01:30:18.355188Z",
      "references": [
        {
          "type": "ADVISORY",
          "url": "https://github.com/cleanstart-dev/cleanstart-security-advisories/tree/main/advisories/2026/CLEANSTART-2026-PE88816.json"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-47912"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-58183"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-58185"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-58186"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-58187"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-58188"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-58189"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-61723"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-61724"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-61725"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-61729"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-25680"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-25681"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-27136"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-27140"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-27143"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-27144"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-27145"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-29181"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-32280"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-32281"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-32282"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-32283"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-32288"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-32289"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-33811"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-33814"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-33818"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-35206"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-35469"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39817"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39819"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39820"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39821"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39823"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39824"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39825"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39826"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39827"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39828"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39829"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39830"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39831"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39832"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39833"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39834"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39835"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39836"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39883"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-41178"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42499"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42501"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42502"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42504"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42506"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42507"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42508"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-46595"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-46597"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-46598"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-46600"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-46680"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-47262"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-50163"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-53488"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56853"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56858"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56859"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56860"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56862"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-259r-337f-4rfw"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-fqw6-gf59-qr4w"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-gcjh-h69q-9w9g"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-hfvc-g4fc-pqhx"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-hr2v-4r36-88hr"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-hrxh-6v49-42gf"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-jpcc-p29g-p8mq"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-mh2q-q3fh-2475"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-pc3f-x583-g7j2"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-xhf5-7wjv-pqxp"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47912"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58183"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58185"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58186"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58187"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58188"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58189"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61723"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61724"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61725"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61729"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25680"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25681"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27136"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27140"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27143"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27144"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27145"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-29181"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32280"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32281"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32282"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32283"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32288"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32289"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33811"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33814"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33818"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-35206"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-35469"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39817"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39819"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39820"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39821"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39823"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39824"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39825"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39826"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39827"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39828"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39829"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39830"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39831"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39832"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39833"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39834"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39835"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39836"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39883"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41178"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42499"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42501"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42502"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42504"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42506"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42507"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42508"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46595"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46597"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46598"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46600"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46680"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-47262"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-50163"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-53488"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56853"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56858"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56859"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56860"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56862"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "severity": [
        {
          "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "type": "CVSS_V3"
        }
      ],
      "summary": "ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label",
      "upstream": [
        "CVE-2025-47912",
        "CVE-2025-58183",
        "CVE-2025-58185",
        "CVE-2025-58186",
        "CVE-2025-58187",
        "CVE-2025-58188",
        "CVE-2025-58189",
        "CVE-2025-61723",
        "CVE-2025-61724",
        "CVE-2025-61725",
        "CVE-2025-61729",
        "CVE-2026-25680",
        "CVE-2026-25681",
        "CVE-2026-27136",
        "CVE-2026-27140",
        "CVE-2026-27143",
        "CVE-2026-27144",
        "CVE-2026-27145",
        "CVE-2026-29181",
        "CVE-2026-32280",
        "CVE-2026-32281",
        "CVE-2026-32282",
        "CVE-2026-32283",
        "CVE-2026-32288",
        "CVE-2026-32289",
        "CVE-2026-33811",
        "CVE-2026-33814",
        "CVE-2026-33818",
        "CVE-2026-35206",
        "CVE-2026-35469",
        "CVE-2026-39817",
        "CVE-2026-39819",
        "CVE-2026-39820",
        "CVE-2026-39821",
        "CVE-2026-39823",
        "CVE-2026-39824",
        "CVE-2026-39825",
        "CVE-2026-39826",
        "CVE-2026-39827",
        "CVE-2026-39828",
        "CVE-2026-39829",
        "CVE-2026-39830",
        "CVE-2026-39831",
        "CVE-2026-39832",
        "CVE-2026-39833",
        "CVE-2026-39834",
        "CVE-2026-39835",
        "CVE-2026-39836",
        "CVE-2026-39883",
        "CVE-2026-41178",
        "CVE-2026-42499",
        "CVE-2026-42501",
        "CVE-2026-42502",
        "CVE-2026-42504",
        "CVE-2026-42506",
        "CVE-2026-42507",
        "CVE-2026-42508",
        "CVE-2026-46595",
        "CVE-2026-46597",
        "CVE-2026-46598",
        "CVE-2026-46600",
        "CVE-2026-46680",
        "CVE-2026-47262",
        "CVE-2026-50163",
        "CVE-2026-53488",
        "CVE-2026-56853",
        "CVE-2026-56858",
        "CVE-2026-56859",
        "CVE-2026-56860",
        "CVE-2026-56862",
        "ghsa-259r-337f-4rfw",
        "ghsa-fqw6-gf59-qr4w",
        "ghsa-gcjh-h69q-9w9g",
        "ghsa-hfvc-g4fc-pqhx",
        "ghsa-hr2v-4r36-88hr",
        "ghsa-hrxh-6v49-42gf",
        "ghsa-jpcc-p29g-p8mq",
        "ghsa-mh2q-q3fh-2475",
        "ghsa-pc3f-x583-g7j2",
        "ghsa-xhf5-7wjv-pqxp"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-PL26831 (CVE-2026-56860)

    Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    Security fixes in temporal-server 1.30.6-r3
    Details

    Package temporal-server version 1.30.6-r3 fixes 11 vulnerabilities: CVE-2026-56860, CVE-2026-56858, CVE-2026-33818, CVE-2026-46600, CVE-2026-56853...

    References

    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "temporal-server"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "1.30.6-r3"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "1.30.6-r3"
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Package temporal-server version 1.30.6-r3 fixes 11 vulnerabilities: CVE-2026-56860, CVE-2026-56858, CVE-2026-33818, CVE-2026-46600, CVE-2026-56853...",
      "id": "CLEANSTART-2026-PL26831",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-09-01T11:17:16Z",
      "references": [
        {
          "type": "WEB",
          "url": "https://github.com/temporalio/temporal"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "summary": "Security fixes in temporal-server 1.30.6-r3",
      "upstream": [
        "CVE-2026-56860",
        "CVE-2026-56858",
        "CVE-2026-33818",
        "CVE-2026-46600",
        "CVE-2026-56853",
        "CVE-2026-56859",
        "CVE-2026-56862",
        "CVE-2026-39821",
        "ghsa-hrxh-6v49-42gf",
        "CVE-2026-41178",
        "ghsa-259r-337f-4rfw"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-PM77605 (CVE-2023-3955)

    Vulnerability from cleanstart – Published: 2026-08-13 12:10 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    Security fixes in flux-notification-controller-fips 1.9.2-r0
    Details

    Package flux-notification-controller-fips version 1.9.2-r0 fixes 6 vulnerabilities: CVE-2023-3955, CVE-2023-3676, CVE-2019-11250, ghsa-gcjh-h69q-9w9g, ghsa-259r-337f-4rfw...


    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "flux-notification-controller-fips"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "1.9.2-r0"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "1.9.2-r0"
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Package flux-notification-controller-fips version 1.9.2-r0 fixes 6 vulnerabilities: CVE-2023-3955, CVE-2023-3676, CVE-2019-11250, ghsa-gcjh-h69q-9w9g, ghsa-259r-337f-4rfw...",
      "id": "CLEANSTART-2026-PM77605",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-08-13T12:10:09Z",
      "references": [
        {
          "type": "WEB",
          "url": "https://github.com/fluxcd/notification-controller"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "summary": "Security fixes in flux-notification-controller-fips 1.9.2-r0",
      "upstream": [
        "CVE-2023-3955",
        "CVE-2023-3676",
        "CVE-2019-11250",
        "ghsa-gcjh-h69q-9w9g",
        "ghsa-259r-337f-4rfw",
        "ghsa-hrxh-6v49-42gf"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-PO42401 (CVE-2026-53492)

    Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    Security fixes in rancher-fleet-agent 0.15.4-r1
    Details

    Package rancher-fleet-agent version 0.15.4-r1 fixes 39 vulnerabilities: CVE-2026-53492, CVE-2026-50195, CVE-2026-53489, CVE-2026-46680, CVE-2026-53488...

    References

    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "rancher-fleet-agent"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "0.15.4-r1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "0.15.4-r1"
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Package rancher-fleet-agent version 0.15.4-r1 fixes 39 vulnerabilities: CVE-2026-53492, CVE-2026-50195, CVE-2026-53489, CVE-2026-46680, CVE-2026-53488...",
      "id": "CLEANSTART-2026-PO42401",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-09-01T11:17:16Z",
      "references": [
        {
          "type": "WEB",
          "url": "https://github.com/rancher/fleet"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "summary": "Security fixes in rancher-fleet-agent 0.15.4-r1",
      "upstream": [
        "CVE-2026-53492",
        "CVE-2026-50195",
        "CVE-2026-53489",
        "CVE-2026-46680",
        "CVE-2026-53488",
        "CVE-2026-47262",
        "CVE-2026-42508",
        "CVE-2026-39835",
        "CVE-2026-46598",
        "CVE-2026-39828",
        "CVE-2026-39829",
        "CVE-2026-46597",
        "CVE-2026-39830",
        "CVE-2026-39831",
        "CVE-2026-39832",
        "CVE-2026-39833",
        "CVE-2026-39834",
        "CVE-2026-46595",
        "CVE-2026-39827",
        "CVE-2026-33186",
        "ghsa-hrxh-6v49-42gf",
        "CVE-2026-46600",
        "CVE-2026-25681",
        "CVE-2026-27136",
        "CVE-2026-39821",
        "CVE-2026-42502",
        "CVE-2026-42506",
        "CVE-2026-25680",
        "CVE-2026-29181",
        "CVE-2026-35469",
        "CVE-2026-56852",
        "CVE-2026-50163",
        "CVE-2026-48978",
        "CVE-2026-50151",
        "CVE-2026-50162",
        "ghsa-vh4v-2xq2-g5cg",
        "CVE-2026-39824",
        "CVE-2026-35206",
        "ghsa-259r-337f-4rfw"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-PP67363 (CVE-2026-41178)

    Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    Security fixes in newrelic-infrastructure-agent 1.79.0-r1
    Details

    Package newrelic-infrastructure-agent version 1.79.0-r1 fixes 2 vulnerabilities: CVE-2026-41178, ghsa-259r-337f-4rfw


    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "newrelic-infrastructure-agent"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "1.79.0-r1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "1.79.0-r1"
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Package newrelic-infrastructure-agent version 1.79.0-r1 fixes 2 vulnerabilities: CVE-2026-41178, ghsa-259r-337f-4rfw",
      "id": "CLEANSTART-2026-PP67363",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-09-01T11:17:16Z",
      "references": [
        {
          "type": "WEB",
          "url": "https://github.com/newrelic/infrastructure-agent"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "summary": "Security fixes in newrelic-infrastructure-agent 1.79.0-r1",
      "upstream": [
        "CVE-2026-41178",
        "ghsa-259r-337f-4rfw"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-PY48265 (CVE-2026-56860)

    Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    Security fixes in temporal-server 1.30.6-r1
    Details

    Package temporal-server version 1.30.6-r1 fixes 15 vulnerabilities: CVE-2026-56860, CVE-2026-56858, CVE-2026-33818, CVE-2026-46600, CVE-2026-56853...

    References

    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "temporal-server"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "1.30.6-r1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "1.30.6-r1"
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Package temporal-server version 1.30.6-r1 fixes 15 vulnerabilities: CVE-2026-56860, CVE-2026-56858, CVE-2026-33818, CVE-2026-46600, CVE-2026-56853...",
      "id": "CLEANSTART-2026-PY48265",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-09-01T11:17:16Z",
      "references": [
        {
          "type": "WEB",
          "url": "https://github.com/temporalio/temporal"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "summary": "Security fixes in temporal-server 1.30.6-r1",
      "upstream": [
        "CVE-2026-56860",
        "CVE-2026-56858",
        "CVE-2026-33818",
        "CVE-2026-46600",
        "CVE-2026-56853",
        "CVE-2026-56859",
        "CVE-2026-56862",
        "CVE-2026-39821",
        "CVE-2026-5724",
        "CVE-2025-14987",
        "CVE-2025-14986",
        "CVE-2026-5199",
        "ghsa-hrxh-6v49-42gf",
        "CVE-2026-41178",
        "ghsa-259r-337f-4rfw"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-QB39018 (CVE-2026-50195)

    Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    Security fixes in rancher-fleet-agent 0.14.10-r1
    Details

    Package rancher-fleet-agent version 0.14.10-r1 fixes 40 vulnerabilities: CVE-2026-50195, CVE-2026-53492, CVE-2026-46680, CVE-2026-53488, CVE-2026-53489...

    References

    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "rancher-fleet-agent"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "0.14.10-r1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "0.14.10-r1"
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Package rancher-fleet-agent version 0.14.10-r1 fixes 40 vulnerabilities: CVE-2026-50195, CVE-2026-53492, CVE-2026-46680, CVE-2026-53488, CVE-2026-53489...",
      "id": "CLEANSTART-2026-QB39018",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-09-01T11:17:16Z",
      "references": [
        {
          "type": "WEB",
          "url": "https://github.com/rancher/fleet"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "summary": "Security fixes in rancher-fleet-agent 0.14.10-r1",
      "upstream": [
        "CVE-2026-50195",
        "CVE-2026-53492",
        "CVE-2026-46680",
        "CVE-2026-53488",
        "CVE-2026-53489",
        "CVE-2026-47262",
        "CVE-2026-42508",
        "CVE-2026-39835",
        "CVE-2026-46598",
        "CVE-2026-39828",
        "CVE-2026-39829",
        "CVE-2026-46597",
        "CVE-2026-39830",
        "CVE-2026-39831",
        "CVE-2026-39832",
        "CVE-2026-39833",
        "CVE-2026-39834",
        "CVE-2026-46595",
        "CVE-2026-39827",
        "CVE-2026-33186",
        "ghsa-hrxh-6v49-42gf",
        "CVE-2026-25681",
        "CVE-2026-27136",
        "CVE-2026-33814",
        "CVE-2026-46600",
        "CVE-2026-39821",
        "CVE-2026-42502",
        "CVE-2026-42506",
        "CVE-2026-25680",
        "CVE-2026-29181",
        "CVE-2026-35469",
        "CVE-2026-56852",
        "CVE-2026-48978",
        "CVE-2026-50163",
        "CVE-2026-50151",
        "CVE-2026-50162",
        "ghsa-vh4v-2xq2-g5cg",
        "CVE-2026-35206",
        "ghsa-259r-337f-4rfw",
        "CVE-2026-39824"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-QK25151 (CVE-2025-61726)

    Vulnerability from cleanstart – Published: 2026-09-08 01:53 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    Previously, a channel registered in the mux's chanList is not usable until it is established
    Details

    Multiple security vulnerabilities affect the step-issuer package. Previously, a channel registered in the mux's chanList is not usable until it is established. See references for individual vulnerability details.

    References
    https://github.com/cleanstart-dev/cleanstart-secu… ADVISORY
    https://osv.dev/vulnerability/CVE-2025-61726 WEB
    https://osv.dev/vulnerability/CVE-2025-61728 WEB
    https://osv.dev/vulnerability/CVE-2025-61730 WEB
    https://osv.dev/vulnerability/CVE-2025-68121 WEB
    https://osv.dev/vulnerability/CVE-2025-69725 WEB
    https://osv.dev/vulnerability/CVE-2026-25518 WEB
    https://osv.dev/vulnerability/CVE-2026-25679 WEB
    https://osv.dev/vulnerability/CVE-2026-25680 WEB
    https://osv.dev/vulnerability/CVE-2026-25681 WEB
    https://osv.dev/vulnerability/CVE-2026-25793 WEB
    https://osv.dev/vulnerability/CVE-2026-26958 WEB
    https://osv.dev/vulnerability/CVE-2026-27136 WEB
    https://osv.dev/vulnerability/CVE-2026-27139 WEB
    https://osv.dev/vulnerability/CVE-2026-27142 WEB
    https://osv.dev/vulnerability/CVE-2026-27145 WEB
    https://osv.dev/vulnerability/CVE-2026-29181 WEB
    https://osv.dev/vulnerability/CVE-2026-30836 WEB
    https://osv.dev/vulnerability/CVE-2026-32280 WEB
    https://osv.dev/vulnerability/CVE-2026-32281 WEB
    https://osv.dev/vulnerability/CVE-2026-32282 WEB
    https://osv.dev/vulnerability/CVE-2026-32283 WEB
    https://osv.dev/vulnerability/CVE-2026-32288 WEB
    https://osv.dev/vulnerability/CVE-2026-32289 WEB
    https://osv.dev/vulnerability/CVE-2026-33186 WEB
    https://osv.dev/vulnerability/CVE-2026-33811 WEB
    https://osv.dev/vulnerability/CVE-2026-33814 WEB
    https://osv.dev/vulnerability/CVE-2026-33815 WEB
    https://osv.dev/vulnerability/CVE-2026-33816 WEB
    https://osv.dev/vulnerability/CVE-2026-33818 WEB
    https://osv.dev/vulnerability/CVE-2026-34986 WEB
    https://osv.dev/vulnerability/CVE-2026-39820 WEB
    https://osv.dev/vulnerability/CVE-2026-39821 WEB
    https://osv.dev/vulnerability/CVE-2026-39822 WEB
    https://osv.dev/vulnerability/CVE-2026-39823 WEB
    https://osv.dev/vulnerability/CVE-2026-39824 WEB
    https://osv.dev/vulnerability/CVE-2026-39825 WEB
    https://osv.dev/vulnerability/CVE-2026-39826 WEB
    https://osv.dev/vulnerability/CVE-2026-39827 WEB
    https://osv.dev/vulnerability/CVE-2026-39828 WEB
    https://osv.dev/vulnerability/CVE-2026-39829 WEB
    https://osv.dev/vulnerability/CVE-2026-39830 WEB
    https://osv.dev/vulnerability/CVE-2026-39831 WEB
    https://osv.dev/vulnerability/CVE-2026-39832 WEB
    https://osv.dev/vulnerability/CVE-2026-39833 WEB
    https://osv.dev/vulnerability/CVE-2026-39834 WEB
    https://osv.dev/vulnerability/CVE-2026-39835 WEB
    https://osv.dev/vulnerability/CVE-2026-39836 WEB
    https://osv.dev/vulnerability/CVE-2026-40097 WEB
    https://osv.dev/vulnerability/CVE-2026-41178 WEB
    https://osv.dev/vulnerability/CVE-2026-41889 WEB
    https://osv.dev/vulnerability/CVE-2026-42499 WEB
    https://osv.dev/vulnerability/CVE-2026-42502 WEB
    https://osv.dev/vulnerability/CVE-2026-42504 WEB
    https://osv.dev/vulnerability/CVE-2026-42505 WEB
    https://osv.dev/vulnerability/CVE-2026-42506 WEB
    https://osv.dev/vulnerability/CVE-2026-42507 WEB
    https://osv.dev/vulnerability/CVE-2026-42508 WEB
    https://osv.dev/vulnerability/CVE-2026-46595 WEB
    https://osv.dev/vulnerability/CVE-2026-46597 WEB
    https://osv.dev/vulnerability/CVE-2026-46598 WEB
    https://osv.dev/vulnerability/CVE-2026-46600 WEB
    https://osv.dev/vulnerability/CVE-2026-56852 WEB
    https://osv.dev/vulnerability/CVE-2026-56853 WEB
    https://osv.dev/vulnerability/CVE-2026-56854 WEB
    https://osv.dev/vulnerability/CVE-2026-56855 WEB
    https://osv.dev/vulnerability/CVE-2026-56858 WEB
    https://osv.dev/vulnerability/CVE-2026-56859 WEB
    https://osv.dev/vulnerability/CVE-2026-56860 WEB
    https://osv.dev/vulnerability/CVE-2026-56862 WEB
    https://osv.dev/vulnerability/CVE-2026-78662 WEB
    https://osv.dev/vulnerability/CVE-2026-84304 WEB
    https://osv.dev/vulnerability/ghsa-259r-337f-4rfw WEB
    https://osv.dev/vulnerability/ghsa-3fxj-6jh8-hvhx WEB
    https://osv.dev/vulnerability/ghsa-9g5q-2w5x-hmxf WEB
    https://osv.dev/vulnerability/ghsa-hrxh-6v49-42gf WEB
    https://osv.dev/vulnerability/ghsa-rjr7-jggh-pgcp WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-61726 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-61728 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-61730 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-68121 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-69725 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-25518 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-25679 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-25680 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-25681 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-25793 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-26958 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-27136 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-27139 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-27142 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-27145 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-29181 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-30836 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-32280 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-32281 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-32282 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-32283 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-32288 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-32289 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-33186 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-33811 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-33814 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-33815 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-33816 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-33818 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-34986 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39820 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39821 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39822 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39823 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39824 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39825 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39826 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39827 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39828 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39829 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39830 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39831 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39832 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39833 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39834 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39835 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39836 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-40097 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-41178 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-41889 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42499 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42502 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42504 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42505 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42506 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42507 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42508 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-46595 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-46597 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-46598 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-46600 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56852 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56853 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56854 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56855 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56858 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56859 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56860 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56862 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-78662 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-84304 WEB

    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "step-issuer"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "0.9.11-r4"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Multiple security vulnerabilities affect the step-issuer package. Previously, a channel registered in the mux\u0027s chanList is not usable until it is established. See references for individual vulnerability details.",
      "id": "CLEANSTART-2026-QK25151",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-09-08T01:53:49.601507Z",
      "references": [
        {
          "type": "ADVISORY",
          "url": "https://github.com/cleanstart-dev/cleanstart-security-advisories/tree/main/advisories/2026/CLEANSTART-2026-QK25151.json"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-61726"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-61728"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-61730"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-68121"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-69725"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-25518"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-25679"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-25680"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-25681"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-25793"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-26958"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-27136"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-27139"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-27142"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-27145"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-29181"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-30836"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-32280"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-32281"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-32282"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-32283"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-32288"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-32289"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-33186"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-33811"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-33814"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-33815"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-33816"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-33818"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-34986"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39820"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39821"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39822"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39823"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39824"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39825"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39826"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39827"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39828"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39829"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39830"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39831"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39832"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39833"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39834"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39835"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39836"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-40097"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-41178"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-41889"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42499"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42502"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42504"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42505"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42506"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42507"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42508"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-46595"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-46597"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-46598"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-46600"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56852"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56853"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56854"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56855"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56858"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56859"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56860"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56862"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-78662"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-84304"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-259r-337f-4rfw"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-3fxj-6jh8-hvhx"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-9g5q-2w5x-hmxf"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-hrxh-6v49-42gf"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-rjr7-jggh-pgcp"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61726"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61728"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61730"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-68121"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-69725"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25518"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25679"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25680"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25681"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25793"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-26958"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27136"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27139"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27142"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27145"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-29181"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-30836"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32280"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32281"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32282"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32283"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32288"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32289"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33186"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33811"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33814"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33815"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33816"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33818"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-34986"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39820"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39821"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39822"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39823"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39824"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39825"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39826"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39827"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39828"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39829"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39830"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39831"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39832"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39833"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39834"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39835"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39836"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-40097"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41178"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41889"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42499"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42502"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42504"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42505"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42506"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42507"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42508"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46595"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46597"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46598"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46600"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56852"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56853"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56854"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56855"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56858"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56859"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56860"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56862"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78662"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84304"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "severity": [
        {
          "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "type": "CVSS_V3"
        }
      ],
      "summary": "Previously, a channel registered in the mux\u0027s chanList is not usable until it is established",
      "upstream": [
        "CVE-2025-61726",
        "CVE-2025-61728",
        "CVE-2025-61730",
        "CVE-2025-68121",
        "CVE-2025-69725",
        "CVE-2026-25518",
        "CVE-2026-25679",
        "CVE-2026-25680",
        "CVE-2026-25681",
        "CVE-2026-25793",
        "CVE-2026-26958",
        "CVE-2026-27136",
        "CVE-2026-27139",
        "CVE-2026-27142",
        "CVE-2026-27145",
        "CVE-2026-29181",
        "CVE-2026-30836",
        "CVE-2026-32280",
        "CVE-2026-32281",
        "CVE-2026-32282",
        "CVE-2026-32283",
        "CVE-2026-32288",
        "CVE-2026-32289",
        "CVE-2026-33186",
        "CVE-2026-33811",
        "CVE-2026-33814",
        "CVE-2026-33815",
        "CVE-2026-33816",
        "CVE-2026-33818",
        "CVE-2026-34986",
        "CVE-2026-39820",
        "CVE-2026-39821",
        "CVE-2026-39822",
        "CVE-2026-39823",
        "CVE-2026-39824",
        "CVE-2026-39825",
        "CVE-2026-39826",
        "CVE-2026-39827",
        "CVE-2026-39828",
        "CVE-2026-39829",
        "CVE-2026-39830",
        "CVE-2026-39831",
        "CVE-2026-39832",
        "CVE-2026-39833",
        "CVE-2026-39834",
        "CVE-2026-39835",
        "CVE-2026-39836",
        "CVE-2026-40097",
        "CVE-2026-41178",
        "CVE-2026-41889",
        "CVE-2026-42499",
        "CVE-2026-42502",
        "CVE-2026-42504",
        "CVE-2026-42505",
        "CVE-2026-42506",
        "CVE-2026-42507",
        "CVE-2026-42508",
        "CVE-2026-46595",
        "CVE-2026-46597",
        "CVE-2026-46598",
        "CVE-2026-46600",
        "CVE-2026-56852",
        "CVE-2026-56853",
        "CVE-2026-56854",
        "CVE-2026-56855",
        "CVE-2026-56858",
        "CVE-2026-56859",
        "CVE-2026-56860",
        "CVE-2026-56862",
        "CVE-2026-78662",
        "CVE-2026-84304",
        "ghsa-259r-337f-4rfw",
        "ghsa-3fxj-6jh8-hvhx",
        "ghsa-9g5q-2w5x-hmxf",
        "ghsa-hrxh-6v49-42gf",
        "ghsa-rjr7-jggh-pgcp"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-QK89502 (CVE-2025-47912)

    Vulnerability from cleanstart – Published: 2026-09-10 01:06 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label
    Details

    Multiple security vulnerabilities affect the vault-k8s package. The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. See references for individual vulnerability details.

    References
    https://github.com/cleanstart-dev/cleanstart-secu… ADVISORY
    https://osv.dev/vulnerability/CVE-2025-47912 WEB
    https://osv.dev/vulnerability/CVE-2025-58183 WEB
    https://osv.dev/vulnerability/CVE-2025-58185 WEB
    https://osv.dev/vulnerability/CVE-2025-58186 WEB
    https://osv.dev/vulnerability/CVE-2025-58187 WEB
    https://osv.dev/vulnerability/CVE-2025-58188 WEB
    https://osv.dev/vulnerability/CVE-2025-58189 WEB
    https://osv.dev/vulnerability/CVE-2025-61723 WEB
    https://osv.dev/vulnerability/CVE-2025-61724 WEB
    https://osv.dev/vulnerability/CVE-2025-61725 WEB
    https://osv.dev/vulnerability/CVE-2025-61729 WEB
    https://osv.dev/vulnerability/CVE-2026-25680 WEB
    https://osv.dev/vulnerability/CVE-2026-25681 WEB
    https://osv.dev/vulnerability/CVE-2026-27136 WEB
    https://osv.dev/vulnerability/CVE-2026-33811 WEB
    https://osv.dev/vulnerability/CVE-2026-33814 WEB
    https://osv.dev/vulnerability/CVE-2026-33818 WEB
    https://osv.dev/vulnerability/CVE-2026-39817 WEB
    https://osv.dev/vulnerability/CVE-2026-39819 WEB
    https://osv.dev/vulnerability/CVE-2026-39820 WEB
    https://osv.dev/vulnerability/CVE-2026-39821 WEB
    https://osv.dev/vulnerability/CVE-2026-39822 WEB
    https://osv.dev/vulnerability/CVE-2026-39823 WEB
    https://osv.dev/vulnerability/CVE-2026-39824 WEB
    https://osv.dev/vulnerability/CVE-2026-39825 WEB
    https://osv.dev/vulnerability/CVE-2026-39826 WEB
    https://osv.dev/vulnerability/CVE-2026-39827 WEB
    https://osv.dev/vulnerability/CVE-2026-39828 WEB
    https://osv.dev/vulnerability/CVE-2026-39829 WEB
    https://osv.dev/vulnerability/CVE-2026-39830 WEB
    https://osv.dev/vulnerability/CVE-2026-39831 WEB
    https://osv.dev/vulnerability/CVE-2026-39832 WEB
    https://osv.dev/vulnerability/CVE-2026-39833 WEB
    https://osv.dev/vulnerability/CVE-2026-39834 WEB
    https://osv.dev/vulnerability/CVE-2026-39835 WEB
    https://osv.dev/vulnerability/CVE-2026-39836 WEB
    https://osv.dev/vulnerability/CVE-2026-42499 WEB
    https://osv.dev/vulnerability/CVE-2026-42501 WEB
    https://osv.dev/vulnerability/CVE-2026-42502 WEB
    https://osv.dev/vulnerability/CVE-2026-42505 WEB
    https://osv.dev/vulnerability/CVE-2026-42506 WEB
    https://osv.dev/vulnerability/CVE-2026-42508 WEB
    https://osv.dev/vulnerability/CVE-2026-46595 WEB
    https://osv.dev/vulnerability/CVE-2026-46597 WEB
    https://osv.dev/vulnerability/CVE-2026-46598 WEB
    https://osv.dev/vulnerability/CVE-2026-46600 WEB
    https://osv.dev/vulnerability/CVE-2026-56852 WEB
    https://osv.dev/vulnerability/CVE-2026-56853 WEB
    https://osv.dev/vulnerability/CVE-2026-56858 WEB
    https://osv.dev/vulnerability/CVE-2026-56859 WEB
    https://osv.dev/vulnerability/CVE-2026-56860 WEB
    https://osv.dev/vulnerability/CVE-2026-56862 WEB
    https://osv.dev/vulnerability/ghsa-259r-337f-4rfw WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-47912 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-58183 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-58185 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-58186 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-58187 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-58188 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-58189 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-61723 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-61724 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-61725 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-61729 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-25680 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-25681 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-27136 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-33811 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-33814 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-33818 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39817 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39819 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39820 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39821 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39822 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39823 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39824 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39825 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39826 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39827 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39828 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39829 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39830 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39831 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39832 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39833 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39834 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39835 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39836 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42499 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42501 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42502 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42505 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42506 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42508 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-46595 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-46597 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-46598 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-46600 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56852 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56853 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56858 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56859 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56860 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56862 WEB

    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "vault-k8s"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "1.7.4-r0"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Multiple security vulnerabilities affect the vault-k8s package. The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. See references for individual vulnerability details.",
      "id": "CLEANSTART-2026-QK89502",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-09-10T01:06:07.433248Z",
      "references": [
        {
          "type": "ADVISORY",
          "url": "https://github.com/cleanstart-dev/cleanstart-security-advisories/tree/main/advisories/2026/CLEANSTART-2026-QK89502.json"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-47912"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-58183"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-58185"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-58186"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-58187"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-58188"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-58189"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-61723"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-61724"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-61725"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-61729"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-25680"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-25681"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-27136"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-33811"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-33814"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-33818"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39817"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39819"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39820"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39821"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39822"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39823"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39824"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39825"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39826"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39827"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39828"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39829"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39830"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39831"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39832"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39833"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39834"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39835"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39836"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42499"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42501"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42502"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42505"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42506"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42508"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-46595"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-46597"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-46598"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-46600"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56852"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56853"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56858"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56859"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56860"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56862"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-259r-337f-4rfw"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47912"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58183"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58185"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58186"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58187"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58188"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58189"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61723"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61724"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61725"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61729"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25680"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25681"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27136"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33811"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33814"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33818"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39817"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39819"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39820"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39821"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39822"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39823"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39824"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39825"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39826"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39827"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39828"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39829"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39830"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39831"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39832"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39833"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39834"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39835"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39836"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42499"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42501"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42502"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42505"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42506"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42508"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46595"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46597"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46598"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46600"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56852"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56853"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56858"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56859"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56860"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56862"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "severity": [
        {
          "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "type": "CVSS_V3"
        }
      ],
      "summary": "ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label",
      "upstream": [
        "CVE-2025-47912",
        "CVE-2025-58183",
        "CVE-2025-58185",
        "CVE-2025-58186",
        "CVE-2025-58187",
        "CVE-2025-58188",
        "CVE-2025-58189",
        "CVE-2025-61723",
        "CVE-2025-61724",
        "CVE-2025-61725",
        "CVE-2025-61729",
        "CVE-2026-25680",
        "CVE-2026-25681",
        "CVE-2026-27136",
        "CVE-2026-33811",
        "CVE-2026-33814",
        "CVE-2026-33818",
        "CVE-2026-39817",
        "CVE-2026-39819",
        "CVE-2026-39820",
        "CVE-2026-39821",
        "CVE-2026-39822",
        "CVE-2026-39823",
        "CVE-2026-39824",
        "CVE-2026-39825",
        "CVE-2026-39826",
        "CVE-2026-39827",
        "CVE-2026-39828",
        "CVE-2026-39829",
        "CVE-2026-39830",
        "CVE-2026-39831",
        "CVE-2026-39832",
        "CVE-2026-39833",
        "CVE-2026-39834",
        "CVE-2026-39835",
        "CVE-2026-39836",
        "CVE-2026-42499",
        "CVE-2026-42501",
        "CVE-2026-42502",
        "CVE-2026-42505",
        "CVE-2026-42506",
        "CVE-2026-42508",
        "CVE-2026-46595",
        "CVE-2026-46597",
        "CVE-2026-46598",
        "CVE-2026-46600",
        "CVE-2026-56852",
        "CVE-2026-56853",
        "CVE-2026-56858",
        "CVE-2026-56859",
        "CVE-2026-56860",
        "CVE-2026-56862",
        "ghsa-259r-337f-4rfw"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-QN07777 (CVE-2026-2303)

    Vulnerability from cleanstart – Published: 2026-09-10 02:44 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection
    Details

    Multiple security vulnerabilities affect the vault package. Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. See references for individual vulnerability details.

    References
    https://github.com/cleanstart-dev/cleanstart-secu… ADVISORY
    https://osv.dev/vulnerability/CVE-2026-2303 WEB
    https://osv.dev/vulnerability/CVE-2026-25680 WEB
    https://osv.dev/vulnerability/CVE-2026-25681 WEB
    https://osv.dev/vulnerability/CVE-2026-27136 WEB
    https://osv.dev/vulnerability/CVE-2026-32280 WEB
    https://osv.dev/vulnerability/CVE-2026-32281 WEB
    https://osv.dev/vulnerability/CVE-2026-32282 WEB
    https://osv.dev/vulnerability/CVE-2026-32283 WEB
    https://osv.dev/vulnerability/CVE-2026-32288 WEB
    https://osv.dev/vulnerability/CVE-2026-32289 WEB
    https://osv.dev/vulnerability/CVE-2026-32952 WEB
    https://osv.dev/vulnerability/CVE-2026-33186 WEB
    https://osv.dev/vulnerability/CVE-2026-33810 WEB
    https://osv.dev/vulnerability/CVE-2026-33811 WEB
    https://osv.dev/vulnerability/CVE-2026-33814 WEB
    https://osv.dev/vulnerability/CVE-2026-33816 WEB
    https://osv.dev/vulnerability/CVE-2026-33818 WEB
    https://osv.dev/vulnerability/CVE-2026-34040 WEB
    https://osv.dev/vulnerability/CVE-2026-34986 WEB
    https://osv.dev/vulnerability/CVE-2026-39817 WEB
    https://osv.dev/vulnerability/CVE-2026-39819 WEB
    https://osv.dev/vulnerability/CVE-2026-39820 WEB
    https://osv.dev/vulnerability/CVE-2026-39821 WEB
    https://osv.dev/vulnerability/CVE-2026-39822 WEB
    https://osv.dev/vulnerability/CVE-2026-39823 WEB
    https://osv.dev/vulnerability/CVE-2026-39824 WEB
    https://osv.dev/vulnerability/CVE-2026-39825 WEB
    https://osv.dev/vulnerability/CVE-2026-39826 WEB
    https://osv.dev/vulnerability/CVE-2026-39827 WEB
    https://osv.dev/vulnerability/CVE-2026-39828 WEB
    https://osv.dev/vulnerability/CVE-2026-39829 WEB
    https://osv.dev/vulnerability/CVE-2026-39830 WEB
    https://osv.dev/vulnerability/CVE-2026-39831 WEB
    https://osv.dev/vulnerability/CVE-2026-39832 WEB
    https://osv.dev/vulnerability/CVE-2026-39833 WEB
    https://osv.dev/vulnerability/CVE-2026-39834 WEB
    https://osv.dev/vulnerability/CVE-2026-39835 WEB
    https://osv.dev/vulnerability/CVE-2026-39836 WEB
    https://osv.dev/vulnerability/CVE-2026-39883 WEB
    https://osv.dev/vulnerability/CVE-2026-41178 WEB
    https://osv.dev/vulnerability/CVE-2026-41568 WEB
    https://osv.dev/vulnerability/CVE-2026-41602 WEB
    https://osv.dev/vulnerability/CVE-2026-42306 WEB
    https://osv.dev/vulnerability/CVE-2026-42499 WEB
    https://osv.dev/vulnerability/CVE-2026-42501 WEB
    https://osv.dev/vulnerability/CVE-2026-42502 WEB
    https://osv.dev/vulnerability/CVE-2026-42505 WEB
    https://osv.dev/vulnerability/CVE-2026-42506 WEB
    https://osv.dev/vulnerability/CVE-2026-42508 WEB
    https://osv.dev/vulnerability/CVE-2026-44503 WEB
    https://osv.dev/vulnerability/CVE-2026-46595 WEB
    https://osv.dev/vulnerability/CVE-2026-46597 WEB
    https://osv.dev/vulnerability/CVE-2026-46598 WEB
    https://osv.dev/vulnerability/CVE-2026-46600 WEB
    https://osv.dev/vulnerability/CVE-2026-56852 WEB
    https://osv.dev/vulnerability/CVE-2026-56853 WEB
    https://osv.dev/vulnerability/CVE-2026-56855 WEB
    https://osv.dev/vulnerability/CVE-2026-56858 WEB
    https://osv.dev/vulnerability/CVE-2026-56859 WEB
    https://osv.dev/vulnerability/CVE-2026-56860 WEB
    https://osv.dev/vulnerability/CVE-2026-56862 WEB
    https://osv.dev/vulnerability/CVE-2026-73500 WEB
    https://osv.dev/vulnerability/CVE-2026-78662 WEB
    https://osv.dev/vulnerability/CVE-2026-84304 WEB
    https://osv.dev/vulnerability/ghsa-259r-337f-4rfw WEB
    https://osv.dev/vulnerability/ghsa-7j59-v9qr-6fq9 WEB
    https://osv.dev/vulnerability/ghsa-hrxh-6v49-42gf WEB
    https://osv.dev/vulnerability/ghsa-j88v-2chj-qfwx WEB
    https://osv.dev/vulnerability/ghsa-mpwr-8vm7-h73f WEB
    https://osv.dev/vulnerability/ghsa-p77j-4mvh-x3m3 WEB
    https://osv.dev/vulnerability/ghsa-pjcq-xvwq-hhpj WEB
    https://osv.dev/vulnerability/ghsa-w67g-5rqw-f597 WEB
    https://osv.dev/vulnerability/ghsa-wf45-q9ch-q8gh WEB
    https://osv.dev/vulnerability/ghsa-xmrv-pmrh-hhx2 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-2303 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-25680 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-25681 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-27136 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-32280 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-32281 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-32282 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-32283 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-32288 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-32289 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-32952 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-33186 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-33810 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-33811 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-33814 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-33816 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-33818 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-34040 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-34986 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39817 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39819 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39820 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39821 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39822 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39823 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39824 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39825 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39826 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39827 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39828 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39829 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39830 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39831 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39832 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39833 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39834 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39835 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39836 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39883 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-41178 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-41568 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-41602 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42306 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42499 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42501 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42502 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42505 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42506 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42508 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-44503 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-46595 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-46597 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-46598 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-46600 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56852 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56853 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56855 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56858 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56859 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56860 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56862 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-73500 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-78662 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-84304 WEB

    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "vault"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "2.0.0-r1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Multiple security vulnerabilities affect the vault package. Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. See references for individual vulnerability details.",
      "id": "CLEANSTART-2026-QN07777",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-09-10T02:44:41.763845Z",
      "references": [
        {
          "type": "ADVISORY",
          "url": "https://github.com/cleanstart-dev/cleanstart-security-advisories/tree/main/advisories/2026/CLEANSTART-2026-QN07777.json"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-2303"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-25680"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-25681"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-27136"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-32280"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-32281"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-32282"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-32283"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-32288"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-32289"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-32952"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-33186"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-33810"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-33811"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-33814"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-33816"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-33818"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-34040"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-34986"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39817"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39819"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39820"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39821"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39822"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39823"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39824"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39825"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39826"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39827"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39828"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39829"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39830"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39831"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39832"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39833"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39834"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39835"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39836"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39883"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-41178"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-41568"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-41602"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42306"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42499"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42501"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42502"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42505"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42506"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42508"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-44503"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-46595"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-46597"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-46598"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-46600"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56852"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56853"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56855"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56858"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56859"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56860"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56862"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-73500"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-78662"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-84304"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-259r-337f-4rfw"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-7j59-v9qr-6fq9"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-hrxh-6v49-42gf"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-j88v-2chj-qfwx"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-mpwr-8vm7-h73f"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-p77j-4mvh-x3m3"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-pjcq-xvwq-hhpj"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-w67g-5rqw-f597"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-wf45-q9ch-q8gh"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-xmrv-pmrh-hhx2"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-2303"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25680"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25681"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27136"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32280"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32281"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32282"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32283"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32288"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32289"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32952"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33186"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33810"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33811"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33814"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33816"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33818"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-34040"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-34986"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39817"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39819"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39820"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39821"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39822"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39823"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39824"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39825"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39826"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39827"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39828"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39829"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39830"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39831"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39832"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39833"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39834"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39835"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39836"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39883"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41178"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41568"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41602"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42306"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42499"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42501"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42502"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42505"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42506"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42508"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-44503"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46595"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46597"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46598"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46600"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56852"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56853"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56855"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56858"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56859"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56860"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56862"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-73500"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78662"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84304"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "severity": [
        {
          "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "type": "CVSS_V3"
        }
      ],
      "summary": "Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection",
      "upstream": [
        "CVE-2026-2303",
        "CVE-2026-25680",
        "CVE-2026-25681",
        "CVE-2026-27136",
        "CVE-2026-32280",
        "CVE-2026-32281",
        "CVE-2026-32282",
        "CVE-2026-32283",
        "CVE-2026-32288",
        "CVE-2026-32289",
        "CVE-2026-32952",
        "CVE-2026-33186",
        "CVE-2026-33810",
        "CVE-2026-33811",
        "CVE-2026-33814",
        "CVE-2026-33816",
        "CVE-2026-33818",
        "CVE-2026-34040",
        "CVE-2026-34986",
        "CVE-2026-39817",
        "CVE-2026-39819",
        "CVE-2026-39820",
        "CVE-2026-39821",
        "CVE-2026-39822",
        "CVE-2026-39823",
        "CVE-2026-39824",
        "CVE-2026-39825",
        "CVE-2026-39826",
        "CVE-2026-39827",
        "CVE-2026-39828",
        "CVE-2026-39829",
        "CVE-2026-39830",
        "CVE-2026-39831",
        "CVE-2026-39832",
        "CVE-2026-39833",
        "CVE-2026-39834",
        "CVE-2026-39835",
        "CVE-2026-39836",
        "CVE-2026-39883",
        "CVE-2026-41178",
        "CVE-2026-41568",
        "CVE-2026-41602",
        "CVE-2026-42306",
        "CVE-2026-42499",
        "CVE-2026-42501",
        "CVE-2026-42502",
        "CVE-2026-42505",
        "CVE-2026-42506",
        "CVE-2026-42508",
        "CVE-2026-44503",
        "CVE-2026-46595",
        "CVE-2026-46597",
        "CVE-2026-46598",
        "CVE-2026-46600",
        "CVE-2026-56852",
        "CVE-2026-56853",
        "CVE-2026-56855",
        "CVE-2026-56858",
        "CVE-2026-56859",
        "CVE-2026-56860",
        "CVE-2026-56862",
        "CVE-2026-73500",
        "CVE-2026-78662",
        "CVE-2026-84304",
        "ghsa-259r-337f-4rfw",
        "ghsa-7j59-v9qr-6fq9",
        "ghsa-hrxh-6v49-42gf",
        "ghsa-j88v-2chj-qfwx",
        "ghsa-mpwr-8vm7-h73f",
        "ghsa-p77j-4mvh-x3m3",
        "ghsa-pjcq-xvwq-hhpj",
        "ghsa-w67g-5rqw-f597",
        "ghsa-wf45-q9ch-q8gh",
        "ghsa-xmrv-pmrh-hhx2"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-QN49433 (CVE-2026-14362)

    Vulnerability from cleanstart – Published: 2026-09-08 00:44 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    HashiCorp memberlist before version 0
    Details

    Multiple security vulnerabilities affect the weaviate-fips package. HashiCorp memberlist before version 0. See references for individual vulnerability details.

    References

    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "weaviate-fips"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "1.37.14-r0"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Multiple security vulnerabilities affect the weaviate-fips package. HashiCorp memberlist before version 0. See references for individual vulnerability details.",
      "id": "CLEANSTART-2026-QN49433",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-09-08T00:44:14.388523Z",
      "references": [
        {
          "type": "ADVISORY",
          "url": "https://github.com/cleanstart-dev/cleanstart-security-advisories/tree/main/advisories/2026/CLEANSTART-2026-QN49433.json"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-14362"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-2303"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-33811"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-33814"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39817"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39819"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39820"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39823"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39825"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39826"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39836"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42499"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42501"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-259r-337f-4rfw"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-xmrv-pmrh-hhx2"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-14362"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-2303"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33811"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33814"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39817"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39819"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39820"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39823"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39825"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39826"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39836"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42499"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42501"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "severity": [
        {
          "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "type": "CVSS_V3"
        }
      ],
      "summary": "HashiCorp memberlist before version 0",
      "upstream": [
        "CVE-2026-14362",
        "CVE-2026-2303",
        "CVE-2026-33811",
        "CVE-2026-33814",
        "CVE-2026-39817",
        "CVE-2026-39819",
        "CVE-2026-39820",
        "CVE-2026-39823",
        "CVE-2026-39825",
        "CVE-2026-39826",
        "CVE-2026-39836",
        "CVE-2026-42499",
        "CVE-2026-42501",
        "ghsa-259r-337f-4rfw",
        "ghsa-xmrv-pmrh-hhx2"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-QO69280 (CVE-2026-46600)

    Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    Security fixes in tempo 2.9.5-r1
    Details

    Package tempo version 2.9.5-r1 fixes 2 vulnerabilities: CVE-2026-46600, ghsa-259r-337f-4rfw

    References

    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "tempo"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "2.9.5-r1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "2.9.5-r1"
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Package tempo version 2.9.5-r1 fixes 2 vulnerabilities: CVE-2026-46600, ghsa-259r-337f-4rfw",
      "id": "CLEANSTART-2026-QO69280",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-09-01T11:17:16Z",
      "references": [
        {
          "type": "WEB",
          "url": "https://github.com/grafana/tempo"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "summary": "Security fixes in tempo 2.9.5-r1",
      "upstream": [
        "CVE-2026-46600",
        "ghsa-259r-337f-4rfw"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-RC17482 (CVE-2025-15558)

    Vulnerability from cleanstart – Published: 2026-09-10 03:06 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label
    Details

    Multiple security vulnerabilities affect the minio-operator package. The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. See references for individual vulnerability details.

    References
    https://github.com/cleanstart-dev/cleanstart-secu… ADVISORY
    https://osv.dev/vulnerability/CVE-2025-15558 WEB
    https://osv.dev/vulnerability/CVE-2025-22868 WEB
    https://osv.dev/vulnerability/CVE-2025-30204 WEB
    https://osv.dev/vulnerability/CVE-2025-47912 WEB
    https://osv.dev/vulnerability/CVE-2025-58183 WEB
    https://osv.dev/vulnerability/CVE-2025-58185 WEB
    https://osv.dev/vulnerability/CVE-2025-58186 WEB
    https://osv.dev/vulnerability/CVE-2025-58187 WEB
    https://osv.dev/vulnerability/CVE-2025-58188 WEB
    https://osv.dev/vulnerability/CVE-2025-58189 WEB
    https://osv.dev/vulnerability/CVE-2025-61723 WEB
    https://osv.dev/vulnerability/CVE-2025-61724 WEB
    https://osv.dev/vulnerability/CVE-2025-61725 WEB
    https://osv.dev/vulnerability/CVE-2025-61726 WEB
    https://osv.dev/vulnerability/CVE-2025-61727 WEB
    https://osv.dev/vulnerability/CVE-2025-61728 WEB
    https://osv.dev/vulnerability/CVE-2025-61729 WEB
    https://osv.dev/vulnerability/CVE-2025-61730 WEB
    https://osv.dev/vulnerability/CVE-2025-61731 WEB
    https://osv.dev/vulnerability/CVE-2025-61732 WEB
    https://osv.dev/vulnerability/CVE-2025-68119 WEB
    https://osv.dev/vulnerability/CVE-2025-68121 WEB
    https://osv.dev/vulnerability/CVE-2026-25679 WEB
    https://osv.dev/vulnerability/CVE-2026-25680 WEB
    https://osv.dev/vulnerability/CVE-2026-27139 WEB
    https://osv.dev/vulnerability/CVE-2026-27142 WEB
    https://osv.dev/vulnerability/CVE-2026-27145 WEB
    https://osv.dev/vulnerability/CVE-2026-33814 WEB
    https://osv.dev/vulnerability/CVE-2026-33818 WEB
    https://osv.dev/vulnerability/CVE-2026-39821 WEB
    https://osv.dev/vulnerability/CVE-2026-39822 WEB
    https://osv.dev/vulnerability/CVE-2026-39833 WEB
    https://osv.dev/vulnerability/CVE-2026-39836 WEB
    https://osv.dev/vulnerability/CVE-2026-42499 WEB
    https://osv.dev/vulnerability/CVE-2026-42504 WEB
    https://osv.dev/vulnerability/CVE-2026-42505 WEB
    https://osv.dev/vulnerability/CVE-2026-42507 WEB
    https://osv.dev/vulnerability/CVE-2026-42508 WEB
    https://osv.dev/vulnerability/CVE-2026-46595 WEB
    https://osv.dev/vulnerability/CVE-2026-46600 WEB
    https://osv.dev/vulnerability/CVE-2026-56852 WEB
    https://osv.dev/vulnerability/CVE-2026-56853 WEB
    https://osv.dev/vulnerability/CVE-2026-56858 WEB
    https://osv.dev/vulnerability/CVE-2026-56859 WEB
    https://osv.dev/vulnerability/CVE-2026-56860 WEB
    https://osv.dev/vulnerability/CVE-2026-56862 WEB
    https://osv.dev/vulnerability/CVE-2026-56864 WEB
    https://osv.dev/vulnerability/CVE-2026-56865 WEB
    https://osv.dev/vulnerability/ghsa-259r-337f-4rfw WEB
    https://osv.dev/vulnerability/ghsa-6v2p-p543-phr9 WEB
    https://osv.dev/vulnerability/ghsa-f6x5-jh6r-wrfv WEB
    https://osv.dev/vulnerability/ghsa-j5w8-q4qc-rx2x WEB
    https://osv.dev/vulnerability/ghsa-p436-gjf2-799p WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-15558 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-22868 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-30204 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-47912 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-58183 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-58185 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-58186 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-58187 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-58188 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-58189 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-61723 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-61724 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-61725 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-61726 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-61727 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-61728 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-61729 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-61730 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-61731 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-61732 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-68119 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-68121 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-25679 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-25680 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-27139 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-27142 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-27145 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-33814 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-33818 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39821 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39822 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39833 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39836 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42499 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42504 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42505 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42507 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42508 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-46595 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-46600 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56852 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56853 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56858 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56859 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56860 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56862 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56864 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56865 WEB

    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "minio-operator"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "7.1.1-r5"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Multiple security vulnerabilities affect the minio-operator package. The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. See references for individual vulnerability details.",
      "id": "CLEANSTART-2026-RC17482",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-09-10T03:06:12.110499Z",
      "references": [
        {
          "type": "ADVISORY",
          "url": "https://github.com/cleanstart-dev/cleanstart-security-advisories/tree/main/advisories/2026/CLEANSTART-2026-RC17482.json"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-15558"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-22868"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-30204"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-47912"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-58183"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-58185"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-58186"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-58187"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-58188"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-58189"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-61723"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-61724"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-61725"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-61726"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-61727"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-61728"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-61729"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-61730"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-61731"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-61732"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-68119"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-68121"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-25679"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-25680"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-27139"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-27142"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-27145"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-33814"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-33818"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39821"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39822"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39833"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39836"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42499"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42504"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42505"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42507"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42508"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-46595"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-46600"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56852"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56853"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56858"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56859"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56860"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56862"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56864"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56865"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-259r-337f-4rfw"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-6v2p-p543-phr9"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-f6x5-jh6r-wrfv"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-j5w8-q4qc-rx2x"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-p436-gjf2-799p"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-15558"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22868"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30204"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47912"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58183"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58185"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58186"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58187"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58188"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58189"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61723"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61724"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61725"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61726"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61727"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61728"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61729"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61730"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61731"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61732"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-68119"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-68121"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25679"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25680"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27139"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27142"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27145"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33814"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33818"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39821"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39822"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39833"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39836"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42499"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42504"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42505"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42507"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42508"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46595"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46600"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56852"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56853"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56858"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56859"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56860"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56862"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56864"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56865"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "severity": [
        {
          "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "type": "CVSS_V3"
        }
      ],
      "summary": "ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label",
      "upstream": [
        "CVE-2025-15558",
        "CVE-2025-22868",
        "CVE-2025-30204",
        "CVE-2025-47912",
        "CVE-2025-58183",
        "CVE-2025-58185",
        "CVE-2025-58186",
        "CVE-2025-58187",
        "CVE-2025-58188",
        "CVE-2025-58189",
        "CVE-2025-61723",
        "CVE-2025-61724",
        "CVE-2025-61725",
        "CVE-2025-61726",
        "CVE-2025-61727",
        "CVE-2025-61728",
        "CVE-2025-61729",
        "CVE-2025-61730",
        "CVE-2025-61731",
        "CVE-2025-61732",
        "CVE-2025-68119",
        "CVE-2025-68121",
        "CVE-2026-25679",
        "CVE-2026-25680",
        "CVE-2026-27139",
        "CVE-2026-27142",
        "CVE-2026-27145",
        "CVE-2026-33814",
        "CVE-2026-33818",
        "CVE-2026-39821",
        "CVE-2026-39822",
        "CVE-2026-39833",
        "CVE-2026-39836",
        "CVE-2026-42499",
        "CVE-2026-42504",
        "CVE-2026-42505",
        "CVE-2026-42507",
        "CVE-2026-42508",
        "CVE-2026-46595",
        "CVE-2026-46600",
        "CVE-2026-56852",
        "CVE-2026-56853",
        "CVE-2026-56858",
        "CVE-2026-56859",
        "CVE-2026-56860",
        "CVE-2026-56862",
        "CVE-2026-56864",
        "CVE-2026-56865",
        "ghsa-259r-337f-4rfw",
        "ghsa-6v2p-p543-phr9",
        "ghsa-f6x5-jh6r-wrfv",
        "ghsa-j5w8-q4qc-rx2x",
        "ghsa-p436-gjf2-799p"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-RH24736 (GHSA-R277-6W6Q-XMQW)

    Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    Security fixes in grafana 12.4.9-r1
    Details

    Package grafana version 12.4.9-r1 fixes 9 vulnerabilities: ghsa-r277-6w6q-xmqw, CVE-2026-73502, CVE-2026-42151, CVE-2026-44903, CVE-2026-21728...

    References

    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "grafana"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "12.4.9-r1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "12.4.9-r1"
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Package grafana version 12.4.9-r1 fixes 9 vulnerabilities: ghsa-r277-6w6q-xmqw, CVE-2026-73502, CVE-2026-42151, CVE-2026-44903, CVE-2026-21728...",
      "id": "CLEANSTART-2026-RH24736",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-09-01T11:17:16Z",
      "references": [
        {
          "type": "WEB",
          "url": "https://grafana.com"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "summary": "Security fixes in grafana 12.4.9-r1",
      "upstream": [
        "ghsa-r277-6w6q-xmqw",
        "CVE-2026-73502",
        "CVE-2026-42151",
        "CVE-2026-44903",
        "CVE-2026-21728",
        "CVE-2026-28377",
        "ghsa-gcjh-h69q-9w9g",
        "CVE-2026-2303",
        "ghsa-259r-337f-4rfw"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-RM95899 (GHSA-HRXH-6V49-42GF)

    Vulnerability from cleanstart – Published: 2026-08-13 12:10 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    Security fixes in cortex 1.18.1-r4
    Details

    Package cortex version 1.18.1-r4 fixes 3 vulnerabilities: ghsa-hrxh-6v49-42gf, ghsa-259r-337f-4rfw, CVE-2026-41178

    References

    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "cortex"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "1.18.1-r4"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "1.18.1-r4"
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Package cortex version 1.18.1-r4 fixes 3 vulnerabilities: ghsa-hrxh-6v49-42gf, ghsa-259r-337f-4rfw, CVE-2026-41178",
      "id": "CLEANSTART-2026-RM95899",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-08-13T12:10:09Z",
      "references": [
        {
          "type": "WEB",
          "url": "https://github.com/cortexproject/cortex"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "summary": "Security fixes in cortex 1.18.1-r4",
      "upstream": [
        "ghsa-hrxh-6v49-42gf",
        "ghsa-259r-337f-4rfw",
        "CVE-2026-41178"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-RU71621 (GHSA-R277-6W6Q-XMQW)

    Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    Security fixes in grafana 12.4.7-r1
    Details

    Package grafana version 12.4.7-r1 fixes 10 vulnerabilities: ghsa-r277-6w6q-xmqw, ghsa-jpcw-4wr7-c3vq, ghsa-gcjh-h69q-9w9g, CVE-2026-21728, CVE-2026-28377...

    References

    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "grafana"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "12.4.7-r1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "12.4.7-r1"
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Package grafana version 12.4.7-r1 fixes 10 vulnerabilities: ghsa-r277-6w6q-xmqw, ghsa-jpcw-4wr7-c3vq, ghsa-gcjh-h69q-9w9g, CVE-2026-21728, CVE-2026-28377...",
      "id": "CLEANSTART-2026-RU71621",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-09-01T11:17:16Z",
      "references": [
        {
          "type": "WEB",
          "url": "https://grafana.com"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "summary": "Security fixes in grafana 12.4.7-r1",
      "upstream": [
        "ghsa-r277-6w6q-xmqw",
        "ghsa-jpcw-4wr7-c3vq",
        "ghsa-gcjh-h69q-9w9g",
        "CVE-2026-21728",
        "CVE-2026-28377",
        "CVE-2026-42151",
        "CVE-2026-40179",
        "CVE-2026-44903",
        "CVE-2026-2303",
        "ghsa-259r-337f-4rfw"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-SA31637 (CVE-2026-41178)

    Vulnerability from cleanstart – Published: 2026-08-13 12:10 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    Security fixes in knative-net-istio 1.21.4-r2
    Details

    Package knative-net-istio version 1.21.4-r2 fixes 2 vulnerabilities: CVE-2026-41178, ghsa-259r-337f-4rfw


    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "knative-net-istio"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "1.21.4-r2"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "1.21.4-r2"
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Package knative-net-istio version 1.21.4-r2 fixes 2 vulnerabilities: CVE-2026-41178, ghsa-259r-337f-4rfw",
      "id": "CLEANSTART-2026-SA31637",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-08-13T12:10:09Z",
      "references": [
        {
          "type": "WEB",
          "url": "https://github.com/knative-extensions/net-istio"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "summary": "Security fixes in knative-net-istio 1.21.4-r2",
      "upstream": [
        "CVE-2026-41178",
        "ghsa-259r-337f-4rfw"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-SB31025 (CVE-2026-56860)

    Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    Security fixes in prometheus-fips 3.11.3-r1
    Details

    Package prometheus-fips version 3.11.3-r1 fixes 17 vulnerabilities: CVE-2026-56860, CVE-2026-56858, CVE-2026-33818, CVE-2026-46600, CVE-2026-56853...


    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "prometheus-fips"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "3.11.3-r1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "3.11.3-r1"
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Package prometheus-fips version 3.11.3-r1 fixes 17 vulnerabilities: CVE-2026-56860, CVE-2026-56858, CVE-2026-33818, CVE-2026-46600, CVE-2026-56853...",
      "id": "CLEANSTART-2026-SB31025",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-09-01T11:17:16Z",
      "references": [
        {
          "type": "WEB",
          "url": "https://github.com/prometheus/prometheus"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "summary": "Security fixes in prometheus-fips 3.11.3-r1",
      "upstream": [
        "CVE-2026-56860",
        "CVE-2026-56858",
        "CVE-2026-33818",
        "CVE-2026-46600",
        "CVE-2026-56853",
        "CVE-2026-56859",
        "CVE-2026-56862",
        "CVE-2026-39821",
        "CVE-2026-33997",
        "CVE-2026-41567",
        "CVE-2026-42306",
        "CVE-2026-34040",
        "CVE-2026-41568",
        "ghsa-hrxh-6v49-42gf",
        "CVE-2026-2303",
        "CVE-2026-41178",
        "ghsa-259r-337f-4rfw"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-SC87229 (GHSA-HRXH-6V49-42GF)

    Vulnerability from cleanstart – Published: 2026-07-30 07:10 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    Security fixes in rclone 1.73.5-r5
    Details

    Package rclone version 1.73.5-r5 fixes 5 vulnerabilities: ghsa-hrxh-6v49-42gf, ghsa-259r-337f-4rfw, ghsa-3fxj-6jh8-hvhx, ghsa-9g5q-2w5x-hmxf, ghsa-rjr7-jggh-pgcp

    References

    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "rclone"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "1.73.5-r5"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "1.73.5-r5"
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Package rclone version 1.73.5-r5 fixes 5 vulnerabilities: ghsa-hrxh-6v49-42gf, ghsa-259r-337f-4rfw, ghsa-3fxj-6jh8-hvhx, ghsa-9g5q-2w5x-hmxf, ghsa-rjr7-jggh-pgcp",
      "id": "CLEANSTART-2026-SC87229",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-07-30T07:10:53Z",
      "references": [
        {
          "type": "WEB",
          "url": "https://github.com/rclone/rclone"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "summary": "Security fixes in rclone 1.73.5-r5",
      "upstream": [
        "ghsa-hrxh-6v49-42gf",
        "ghsa-259r-337f-4rfw",
        "ghsa-3fxj-6jh8-hvhx",
        "ghsa-9g5q-2w5x-hmxf",
        "ghsa-rjr7-jggh-pgcp"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-SH16039 (GHSA-259R-337F-4RFW)

    Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    Security fixes in ollama-fips 0.32.8-r1
    Details

    Package ollama-fips version 0.32.8-r1 fixes 1 vulnerabilities: ghsa-259r-337f-4rfw

    References

    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "ollama-fips"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "0.32.8-r1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "0.32.8-r1"
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Package ollama-fips version 0.32.8-r1 fixes 1 vulnerabilities: ghsa-259r-337f-4rfw",
      "id": "CLEANSTART-2026-SH16039",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-09-01T11:17:16Z",
      "references": [
        {
          "type": "WEB",
          "url": "https://ollama.com"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "summary": "Security fixes in ollama-fips 0.32.8-r1",
      "upstream": [
        "ghsa-259r-337f-4rfw"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-SK52724 (CVE-2026-54787)

    Vulnerability from cleanstart – Published: 2026-08-13 12:10 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    Security fixes in cosign 3.1.2-r1
    Details

    Package cosign version 3.1.2-r1 fixes 9 vulnerabilities: CVE-2026-54787, ghsa-hrxh-6v49-42gf, ghsa-259r-337f-4rfw, CVE-2026-49835, ghsa-9c54-x2g4-v92j...

    References

    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "cosign"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "3.1.2-r1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "3.1.2-r1"
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Package cosign version 3.1.2-r1 fixes 9 vulnerabilities: CVE-2026-54787, ghsa-hrxh-6v49-42gf, ghsa-259r-337f-4rfw, CVE-2026-49835, ghsa-9c54-x2g4-v92j...",
      "id": "CLEANSTART-2026-SK52724",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-08-13T12:10:09Z",
      "references": [
        {
          "type": "WEB",
          "url": "https://github.com/sigstore/cosign"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "summary": "Security fixes in cosign 3.1.2-r1",
      "upstream": [
        "CVE-2026-54787",
        "ghsa-hrxh-6v49-42gf",
        "ghsa-259r-337f-4rfw",
        "CVE-2026-49835",
        "ghsa-9c54-x2g4-v92j",
        "CVE-2026-49834",
        "ghsa-9vcr-p3rj-q5q6",
        "CVE-2026-48702",
        "ghsa-47q9-m4ww-924m"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-SL17084 (CVE-2026-33186)

    Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    Security fixes in step-ca 0.27.5-r0
    Details

    Package step-ca version 0.27.5-r0 fixes 14 vulnerabilities: CVE-2026-33186, CVE-2025-27144, CVE-2026-34986, CVE-2025-22868, CVE-2026-25793...


    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "step-ca"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "0.27.5-r0"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "0.27.5-r0"
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Package step-ca version 0.27.5-r0 fixes 14 vulnerabilities: CVE-2026-33186, CVE-2025-27144, CVE-2026-34986, CVE-2025-22868, CVE-2026-25793...",
      "id": "CLEANSTART-2026-SL17084",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-09-01T11:17:16Z",
      "references": [
        {
          "type": "WEB",
          "url": "https://github.com/smallstep/certificates"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "summary": "Security fixes in step-ca 0.27.5-r0",
      "upstream": [
        "CVE-2026-33186",
        "CVE-2025-27144",
        "CVE-2026-34986",
        "CVE-2025-22868",
        "CVE-2026-25793",
        "CVE-2025-62820",
        "CVE-2024-45339",
        "CVE-2026-26958",
        "CVE-2025-30204",
        "ghsa-vrw8-fxc6-2r93",
        "ghsa-9g5q-2w5x-hmxf",
        "ghsa-rjr7-jggh-pgcp",
        "ghsa-259r-337f-4rfw",
        "ghsa-hrxh-6v49-42gf"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-SP46945 (CVE-2026-39828)

    Vulnerability from cleanstart – Published: 2026-08-13 12:10 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    Security fixes in percona-server-mongodb-operator 1.23.0-r0
    Details

    Package percona-server-mongodb-operator version 1.23.0-r0 fixes 22 vulnerabilities: CVE-2026-39828, CVE-2026-39829, CVE-2026-39830, CVE-2026-39831, CVE-2026-39832...


    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "percona-server-mongodb-operator"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "1.23.0-r0"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "1.23.0-r0"
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Package percona-server-mongodb-operator version 1.23.0-r0 fixes 22 vulnerabilities: CVE-2026-39828, CVE-2026-39829, CVE-2026-39830, CVE-2026-39831, CVE-2026-39832...",
      "id": "CLEANSTART-2026-SP46945",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-08-13T12:10:09Z",
      "references": [
        {
          "type": "WEB",
          "url": "https://github.com/percona/percona-server-mongodb-operator.git"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "summary": "Security fixes in percona-server-mongodb-operator 1.23.0-r0",
      "upstream": [
        "CVE-2026-39828",
        "CVE-2026-39829",
        "CVE-2026-39830",
        "CVE-2026-39831",
        "CVE-2026-39832",
        "CVE-2026-39835",
        "CVE-2026-42508",
        "CVE-2026-46595",
        "CVE-2026-46597",
        "CVE-2026-39827",
        "CVE-2026-39833",
        "CVE-2026-39834",
        "CVE-2026-46598",
        "CVE-2026-25681",
        "CVE-2026-27136",
        "CVE-2026-39821",
        "CVE-2026-25680",
        "CVE-2026-42502",
        "CVE-2026-42506",
        "CVE-2026-46600",
        "CVE-2026-56852",
        "ghsa-259r-337f-4rfw"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-SS10950 (CVE-2026-46603)

    Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    Security fixes in gitea 1.27.2-r1
    Details

    Package gitea version 1.27.2-r1 fixes 9 vulnerabilities: CVE-2026-46603, CVE-2026-56864, CVE-2026-56865, CVE-2026-71556, CVE-2026-71557...

    References

    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "gitea"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "1.27.2-r1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "1.27.2-r1"
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Package gitea version 1.27.2-r1 fixes 9 vulnerabilities: CVE-2026-46603, CVE-2026-56864, CVE-2026-56865, CVE-2026-71556, CVE-2026-71557...",
      "id": "CLEANSTART-2026-SS10950",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-09-01T11:17:16Z",
      "references": [
        {
          "type": "WEB",
          "url": "https://github.com/go-gitea/gitea"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "summary": "Security fixes in gitea 1.27.2-r1",
      "upstream": [
        "CVE-2026-46603",
        "CVE-2026-56864",
        "CVE-2026-56865",
        "CVE-2026-71556",
        "CVE-2026-71557",
        "ghsa-259r-337f-4rfw",
        "ghsa-3fxj-6jh8-hvhx",
        "ghsa-9g5q-2w5x-hmxf",
        "ghsa-rjr7-jggh-pgcg"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-SU87029 (GHSA-259R-337F-4RFW)

    Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    Security fixes in argo-cd 3.3.12-r4
    Details

    Package argo-cd version 3.3.12-r4 fixes 2 vulnerabilities: ghsa-259r-337f-4rfw, CVE-2026-41178

    References

    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "argo-cd"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "3.3.12-r4"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "3.3.12-r4"
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Package argo-cd version 3.3.12-r4 fixes 2 vulnerabilities: ghsa-259r-337f-4rfw, CVE-2026-41178",
      "id": "CLEANSTART-2026-SU87029",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-09-01T11:17:16Z",
      "references": [
        {
          "type": "WEB",
          "url": "https://github.com/argoproj/argo-cd"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "summary": "Security fixes in argo-cd 3.3.12-r4",
      "upstream": [
        "ghsa-259r-337f-4rfw",
        "CVE-2026-41178"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-TD50332 (CVE-2026-56860)

    Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    Security fixes in local-path-provisioner-fips 0.0.36-r1
    Details

    Package local-path-provisioner-fips version 0.0.36-r1 fixes 19 vulnerabilities: CVE-2026-56860, CVE-2026-56858, CVE-2026-33818, CVE-2026-56853, CVE-2026-56859...


    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "local-path-provisioner-fips"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "0.0.36-r1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "0.0.36-r1"
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Package local-path-provisioner-fips version 0.0.36-r1 fixes 19 vulnerabilities: CVE-2026-56860, CVE-2026-56858, CVE-2026-33818, CVE-2026-56853, CVE-2026-56859...",
      "id": "CLEANSTART-2026-TD50332",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-09-01T11:17:16Z",
      "references": [
        {
          "type": "WEB",
          "url": "https://github.com/rancher/local-path-provisioner"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "summary": "Security fixes in local-path-provisioner-fips 0.0.36-r1",
      "upstream": [
        "CVE-2026-56860",
        "CVE-2026-56858",
        "CVE-2026-33818",
        "CVE-2026-56853",
        "CVE-2026-56859",
        "CVE-2026-56862",
        "CVE-2026-46600",
        "CVE-2026-25681",
        "CVE-2026-27136",
        "CVE-2026-33814",
        "CVE-2026-39821",
        "CVE-2025-47911",
        "CVE-2025-58190",
        "CVE-2026-42502",
        "CVE-2026-42506",
        "CVE-2026-25680",
        "CVE-2026-39824",
        "CVE-2026-56852",
        "ghsa-259r-337f-4rfw"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-TJ10436 (GHSA-259R-337F-4RFW)

    Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    Security fixes in ollama 0.31.2-r1
    Details

    Package ollama version 0.31.2-r1 fixes 1 vulnerabilities: ghsa-259r-337f-4rfw

    References

    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "ollama"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "0.31.2-r1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "0.31.2-r1"
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Package ollama version 0.31.2-r1 fixes 1 vulnerabilities: ghsa-259r-337f-4rfw",
      "id": "CLEANSTART-2026-TJ10436",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-09-01T11:17:16Z",
      "references": [
        {
          "type": "WEB",
          "url": "https://ollama.com"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "summary": "Security fixes in ollama 0.31.2-r1",
      "upstream": [
        "ghsa-259r-337f-4rfw"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-TO35695 (CVE-2026-24051)

    Vulnerability from cleanstart – Published: 2026-09-16 01:06 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection
    Details

    Multiple security vulnerabilities affect the cert-manager package. Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. See references for individual vulnerability details.

    References
    https://github.com/cleanstart-dev/cleanstart-secu… ADVISORY
    https://osv.dev/vulnerability/CVE-2026-24051 WEB
    https://osv.dev/vulnerability/CVE-2026-25680 WEB
    https://osv.dev/vulnerability/CVE-2026-25681 WEB
    https://osv.dev/vulnerability/CVE-2026-27136 WEB
    https://osv.dev/vulnerability/CVE-2026-27145 WEB
    https://osv.dev/vulnerability/CVE-2026-32952 WEB
    https://osv.dev/vulnerability/CVE-2026-33186 WEB
    https://osv.dev/vulnerability/CVE-2026-33811 WEB
    https://osv.dev/vulnerability/CVE-2026-33814 WEB
    https://osv.dev/vulnerability/CVE-2026-33818 WEB
    https://osv.dev/vulnerability/CVE-2026-34986 WEB
    https://osv.dev/vulnerability/CVE-2026-39820 WEB
    https://osv.dev/vulnerability/CVE-2026-39821 WEB
    https://osv.dev/vulnerability/CVE-2026-39822 WEB
    https://osv.dev/vulnerability/CVE-2026-39823 WEB
    https://osv.dev/vulnerability/CVE-2026-39824 WEB
    https://osv.dev/vulnerability/CVE-2026-39825 WEB
    https://osv.dev/vulnerability/CVE-2026-39826 WEB
    https://osv.dev/vulnerability/CVE-2026-39827 WEB
    https://osv.dev/vulnerability/CVE-2026-39828 WEB
    https://osv.dev/vulnerability/CVE-2026-39829 WEB
    https://osv.dev/vulnerability/CVE-2026-39830 WEB
    https://osv.dev/vulnerability/CVE-2026-39831 WEB
    https://osv.dev/vulnerability/CVE-2026-39832 WEB
    https://osv.dev/vulnerability/CVE-2026-39833 WEB
    https://osv.dev/vulnerability/CVE-2026-39834 WEB
    https://osv.dev/vulnerability/CVE-2026-39835 WEB
    https://osv.dev/vulnerability/CVE-2026-39836 WEB
    https://osv.dev/vulnerability/CVE-2026-39883 WEB
    https://osv.dev/vulnerability/CVE-2026-41178 WEB
    https://osv.dev/vulnerability/CVE-2026-42499 WEB
    https://osv.dev/vulnerability/CVE-2026-42502 WEB
    https://osv.dev/vulnerability/CVE-2026-42504 WEB
    https://osv.dev/vulnerability/CVE-2026-42505 WEB
    https://osv.dev/vulnerability/CVE-2026-42506 WEB
    https://osv.dev/vulnerability/CVE-2026-42507 WEB
    https://osv.dev/vulnerability/CVE-2026-42508 WEB
    https://osv.dev/vulnerability/CVE-2026-46595 WEB
    https://osv.dev/vulnerability/CVE-2026-46597 WEB
    https://osv.dev/vulnerability/CVE-2026-46598 WEB
    https://osv.dev/vulnerability/CVE-2026-46600 WEB
    https://osv.dev/vulnerability/CVE-2026-56852 WEB
    https://osv.dev/vulnerability/CVE-2026-56853 WEB
    https://osv.dev/vulnerability/CVE-2026-56855 WEB
    https://osv.dev/vulnerability/CVE-2026-56858 WEB
    https://osv.dev/vulnerability/CVE-2026-56859 WEB
    https://osv.dev/vulnerability/CVE-2026-56860 WEB
    https://osv.dev/vulnerability/CVE-2026-56862 WEB
    https://osv.dev/vulnerability/CVE-2026-73500 WEB
    https://osv.dev/vulnerability/CVE-2026-78662 WEB
    https://osv.dev/vulnerability/CVE-2026-84303 WEB
    https://osv.dev/vulnerability/CVE-2026-84304 WEB
    https://osv.dev/vulnerability/CVE-2026-84445 WEB
    https://osv.dev/vulnerability/ghsa-259r-337f-4rfw WEB
    https://osv.dev/vulnerability/ghsa-78h2-9frx-2jm8 WEB
    https://osv.dev/vulnerability/ghsa-9h8m-3fm2-qjrq WEB
    https://osv.dev/vulnerability/ghsa-gcjh-h69q-9w9g WEB
    https://osv.dev/vulnerability/ghsa-hrxh-6v49-42gf WEB
    https://osv.dev/vulnerability/ghsa-p77j-4mvh-x3m3 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-24051 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-25680 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-25681 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-27136 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-27145 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-32952 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-33186 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-33811 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-33814 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-33818 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-34986 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39820 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39821 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39822 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39823 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39824 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39825 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39826 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39827 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39828 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39829 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39830 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39831 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39832 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39833 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39834 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39835 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39836 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39883 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-41178 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42499 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42502 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42504 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42505 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42506 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42507 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42508 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-46595 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-46597 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-46598 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-46600 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56852 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56853 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56855 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56858 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56859 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56860 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56862 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-73500 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-78662 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-84303 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-84304 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-84445 WEB

    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "cert-manager"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "1.19.2-r0"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Multiple security vulnerabilities affect the cert-manager package. Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. See references for individual vulnerability details.",
      "id": "CLEANSTART-2026-TO35695",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-09-16T01:06:44.709827Z",
      "references": [
        {
          "type": "ADVISORY",
          "url": "https://github.com/cleanstart-dev/cleanstart-security-advisories/tree/main/advisories/2026/CLEANSTART-2026-TO35695.json"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-24051"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-25680"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-25681"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-27136"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-27145"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-32952"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-33186"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-33811"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-33814"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-33818"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-34986"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39820"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39821"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39822"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39823"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39824"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39825"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39826"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39827"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39828"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39829"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39830"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39831"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39832"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39833"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39834"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39835"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39836"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39883"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-41178"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42499"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42502"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42504"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42505"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42506"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42507"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42508"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-46595"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-46597"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-46598"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-46600"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56852"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56853"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56855"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56858"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56859"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56860"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56862"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-73500"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-78662"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-84303"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-84304"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-84445"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-259r-337f-4rfw"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-78h2-9frx-2jm8"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-9h8m-3fm2-qjrq"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-gcjh-h69q-9w9g"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-hrxh-6v49-42gf"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-p77j-4mvh-x3m3"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-24051"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25680"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25681"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27136"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27145"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32952"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33186"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33811"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33814"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33818"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-34986"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39820"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39821"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39822"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39823"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39824"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39825"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39826"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39827"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39828"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39829"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39830"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39831"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39832"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39833"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39834"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39835"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39836"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39883"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41178"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42499"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42502"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42504"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42505"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42506"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42507"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42508"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46595"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46597"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46598"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46600"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56852"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56853"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56855"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56858"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56859"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56860"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56862"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-73500"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78662"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84303"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84304"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84445"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "severity": [
        {
          "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "type": "CVSS_V3"
        }
      ],
      "summary": "Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection",
      "upstream": [
        "CVE-2026-24051",
        "CVE-2026-25680",
        "CVE-2026-25681",
        "CVE-2026-27136",
        "CVE-2026-27145",
        "CVE-2026-32952",
        "CVE-2026-33186",
        "CVE-2026-33811",
        "CVE-2026-33814",
        "CVE-2026-33818",
        "CVE-2026-34986",
        "CVE-2026-39820",
        "CVE-2026-39821",
        "CVE-2026-39822",
        "CVE-2026-39823",
        "CVE-2026-39824",
        "CVE-2026-39825",
        "CVE-2026-39826",
        "CVE-2026-39827",
        "CVE-2026-39828",
        "CVE-2026-39829",
        "CVE-2026-39830",
        "CVE-2026-39831",
        "CVE-2026-39832",
        "CVE-2026-39833",
        "CVE-2026-39834",
        "CVE-2026-39835",
        "CVE-2026-39836",
        "CVE-2026-39883",
        "CVE-2026-41178",
        "CVE-2026-42499",
        "CVE-2026-42502",
        "CVE-2026-42504",
        "CVE-2026-42505",
        "CVE-2026-42506",
        "CVE-2026-42507",
        "CVE-2026-42508",
        "CVE-2026-46595",
        "CVE-2026-46597",
        "CVE-2026-46598",
        "CVE-2026-46600",
        "CVE-2026-56852",
        "CVE-2026-56853",
        "CVE-2026-56855",
        "CVE-2026-56858",
        "CVE-2026-56859",
        "CVE-2026-56860",
        "CVE-2026-56862",
        "CVE-2026-73500",
        "CVE-2026-78662",
        "CVE-2026-84303",
        "CVE-2026-84304",
        "CVE-2026-84445",
        "ghsa-259r-337f-4rfw",
        "ghsa-78h2-9frx-2jm8",
        "ghsa-9h8m-3fm2-qjrq",
        "ghsa-gcjh-h69q-9w9g",
        "ghsa-hrxh-6v49-42gf",
        "ghsa-p77j-4mvh-x3m3"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-TR82670 (GHSA-259R-337F-4RFW)

    Vulnerability from cleanstart – Published: 2026-07-30 07:10 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    Security fixes in prometheus-redis-exporter 1.87.0-r0
    Details

    Package prometheus-redis-exporter version 1.87.0-r0 fixes 1 vulnerabilities: ghsa-259r-337f-4rfw


    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "prometheus-redis-exporter"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "1.87.0-r0"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "1.87.0-r0"
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Package prometheus-redis-exporter version 1.87.0-r0 fixes 1 vulnerabilities: ghsa-259r-337f-4rfw",
      "id": "CLEANSTART-2026-TR82670",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-07-30T07:10:53Z",
      "references": [
        {
          "type": "WEB",
          "url": "https://github.com/oliver006/redis_exporter"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "summary": "Security fixes in prometheus-redis-exporter 1.87.0-r0",
      "upstream": [
        "ghsa-259r-337f-4rfw"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-TX42489 (GHSA-HRXH-6V49-42GF)

    Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    Security fixes in pulumi 3.248.0-r0
    Details

    Package pulumi version 3.248.0-r0 fixes 30 vulnerabilities: ghsa-hrxh-6v49-42gf, CVE-2026-56864, CVE-2026-56865, CVE-2026-56852, CVE-2026-71556...

    References

    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "pulumi"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "3.248.0-r0"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "3.248.0-r0"
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Package pulumi version 3.248.0-r0 fixes 30 vulnerabilities: ghsa-hrxh-6v49-42gf, CVE-2026-56864, CVE-2026-56865, CVE-2026-56852, CVE-2026-71556...",
      "id": "CLEANSTART-2026-TX42489",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-09-01T11:17:16Z",
      "references": [
        {
          "type": "WEB",
          "url": "https://github.com/pulumi/pulumi"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "summary": "Security fixes in pulumi 3.248.0-r0",
      "upstream": [
        "ghsa-hrxh-6v49-42gf",
        "CVE-2026-56864",
        "CVE-2026-56865",
        "CVE-2026-56852",
        "CVE-2026-71556",
        "CVE-2026-71557",
        "ghsa-259r-337f-4rfw",
        "CVE-2026-5160",
        "CVE-2026-59873",
        "CVE-2026-59871",
        "CVE-2026-59874",
        "CVE-2026-59875",
        "CVE-2026-53655",
        "ghsa-r292-9mhp-454m",
        "CVE-2026-59869",
        "ghsa-5p4m-2wfm-xmqj",
        "CVE-2026-45149",
        "CVE-2026-14257",
        "CVE-2026-69152",
        "CVE-2026-13149",
        "CVE-2026-54285",
        "CVE-2026-59892",
        "CVE-2026-59877",
        "CVE-2026-9496",
        "CVE-2026-9358",
        "CVE-2026-69192",
        "CVE-2026-42338",
        "CVE-2026-48758",
        "CVE-2026-48815",
        "CVE-2026-48816"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-TY53144 (CVE-2026-2303)

    Vulnerability from cleanstart – Published: 2026-09-10 02:43 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection
    Details

    Multiple security vulnerabilities affect the vault package. Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. See references for individual vulnerability details.

    References
    https://github.com/cleanstart-dev/cleanstart-secu… ADVISORY
    https://osv.dev/vulnerability/CVE-2026-2303 WEB
    https://osv.dev/vulnerability/CVE-2026-25680 WEB
    https://osv.dev/vulnerability/CVE-2026-25681 WEB
    https://osv.dev/vulnerability/CVE-2026-27136 WEB
    https://osv.dev/vulnerability/CVE-2026-27145 WEB
    https://osv.dev/vulnerability/CVE-2026-32280 WEB
    https://osv.dev/vulnerability/CVE-2026-32281 WEB
    https://osv.dev/vulnerability/CVE-2026-32282 WEB
    https://osv.dev/vulnerability/CVE-2026-32283 WEB
    https://osv.dev/vulnerability/CVE-2026-32288 WEB
    https://osv.dev/vulnerability/CVE-2026-32289 WEB
    https://osv.dev/vulnerability/CVE-2026-32952 WEB
    https://osv.dev/vulnerability/CVE-2026-33186 WEB
    https://osv.dev/vulnerability/CVE-2026-33810 WEB
    https://osv.dev/vulnerability/CVE-2026-33811 WEB
    https://osv.dev/vulnerability/CVE-2026-33814 WEB
    https://osv.dev/vulnerability/CVE-2026-33816 WEB
    https://osv.dev/vulnerability/CVE-2026-33818 WEB
    https://osv.dev/vulnerability/CVE-2026-34040 WEB
    https://osv.dev/vulnerability/CVE-2026-34986 WEB
    https://osv.dev/vulnerability/CVE-2026-39817 WEB
    https://osv.dev/vulnerability/CVE-2026-39819 WEB
    https://osv.dev/vulnerability/CVE-2026-39820 WEB
    https://osv.dev/vulnerability/CVE-2026-39821 WEB
    https://osv.dev/vulnerability/CVE-2026-39822 WEB
    https://osv.dev/vulnerability/CVE-2026-39823 WEB
    https://osv.dev/vulnerability/CVE-2026-39824 WEB
    https://osv.dev/vulnerability/CVE-2026-39825 WEB
    https://osv.dev/vulnerability/CVE-2026-39826 WEB
    https://osv.dev/vulnerability/CVE-2026-39827 WEB
    https://osv.dev/vulnerability/CVE-2026-39828 WEB
    https://osv.dev/vulnerability/CVE-2026-39829 WEB
    https://osv.dev/vulnerability/CVE-2026-39830 WEB
    https://osv.dev/vulnerability/CVE-2026-39831 WEB
    https://osv.dev/vulnerability/CVE-2026-39832 WEB
    https://osv.dev/vulnerability/CVE-2026-39833 WEB
    https://osv.dev/vulnerability/CVE-2026-39834 WEB
    https://osv.dev/vulnerability/CVE-2026-39835 WEB
    https://osv.dev/vulnerability/CVE-2026-39836 WEB
    https://osv.dev/vulnerability/CVE-2026-39883 WEB
    https://osv.dev/vulnerability/CVE-2026-41178 WEB
    https://osv.dev/vulnerability/CVE-2026-41602 WEB
    https://osv.dev/vulnerability/CVE-2026-41889 WEB
    https://osv.dev/vulnerability/CVE-2026-42499 WEB
    https://osv.dev/vulnerability/CVE-2026-42501 WEB
    https://osv.dev/vulnerability/CVE-2026-42502 WEB
    https://osv.dev/vulnerability/CVE-2026-42504 WEB
    https://osv.dev/vulnerability/CVE-2026-42505 WEB
    https://osv.dev/vulnerability/CVE-2026-42506 WEB
    https://osv.dev/vulnerability/CVE-2026-42507 WEB
    https://osv.dev/vulnerability/CVE-2026-42508 WEB
    https://osv.dev/vulnerability/CVE-2026-43871 WEB
    https://osv.dev/vulnerability/CVE-2026-44503 WEB
    https://osv.dev/vulnerability/CVE-2026-46595 WEB
    https://osv.dev/vulnerability/CVE-2026-46597 WEB
    https://osv.dev/vulnerability/CVE-2026-46598 WEB
    https://osv.dev/vulnerability/CVE-2026-46600 WEB
    https://osv.dev/vulnerability/CVE-2026-56852 WEB
    https://osv.dev/vulnerability/CVE-2026-56853 WEB
    https://osv.dev/vulnerability/CVE-2026-56855 WEB
    https://osv.dev/vulnerability/CVE-2026-56858 WEB
    https://osv.dev/vulnerability/CVE-2026-56859 WEB
    https://osv.dev/vulnerability/CVE-2026-56860 WEB
    https://osv.dev/vulnerability/CVE-2026-56862 WEB
    https://osv.dev/vulnerability/CVE-2026-73500 WEB
    https://osv.dev/vulnerability/CVE-2026-78662 WEB
    https://osv.dev/vulnerability/CVE-2026-84304 WEB
    https://osv.dev/vulnerability/ghsa-259r-337f-4rfw WEB
    https://osv.dev/vulnerability/ghsa-7j59-v9qr-6fq9 WEB
    https://osv.dev/vulnerability/ghsa-cp6g-7hqx-qxhp WEB
    https://osv.dev/vulnerability/ghsa-hrxh-6v49-42gf WEB
    https://osv.dev/vulnerability/ghsa-j88v-2chj-qfwx WEB
    https://osv.dev/vulnerability/ghsa-p77j-4mvh-x3m3 WEB
    https://osv.dev/vulnerability/ghsa-pjcq-xvwq-hhpj WEB
    https://osv.dev/vulnerability/ghsa-wf45-q9ch-q8gh WEB
    https://osv.dev/vulnerability/ghsa-xmrv-pmrh-hhx2 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-2303 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-25680 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-25681 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-27136 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-27145 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-32280 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-32281 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-32282 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-32283 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-32288 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-32289 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-32952 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-33186 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-33810 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-33811 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-33814 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-33816 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-33818 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-34040 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-34986 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39817 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39819 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39820 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39821 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39822 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39823 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39824 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39825 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39826 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39827 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39828 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39829 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39830 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39831 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39832 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39833 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39834 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39835 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39836 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39883 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-41178 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-41602 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-41889 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42499 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42501 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42502 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42504 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42505 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42506 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42507 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42508 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-43871 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-44503 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-46595 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-46597 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-46598 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-46600 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56852 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56853 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56855 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56858 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56859 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56860 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56862 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-73500 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-78662 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-84304 WEB

    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "vault"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "1.21.4-r9"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Multiple security vulnerabilities affect the vault package. Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. See references for individual vulnerability details.",
      "id": "CLEANSTART-2026-TY53144",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-09-10T02:43:42.648597Z",
      "references": [
        {
          "type": "ADVISORY",
          "url": "https://github.com/cleanstart-dev/cleanstart-security-advisories/tree/main/advisories/2026/CLEANSTART-2026-TY53144.json"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-2303"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-25680"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-25681"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-27136"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-27145"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-32280"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-32281"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-32282"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-32283"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-32288"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-32289"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-32952"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-33186"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-33810"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-33811"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-33814"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-33816"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-33818"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-34040"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-34986"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39817"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39819"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39820"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39821"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39822"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39823"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39824"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39825"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39826"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39827"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39828"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39829"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39830"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39831"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39832"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39833"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39834"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39835"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39836"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39883"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-41178"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-41602"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-41889"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42499"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42501"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42502"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42504"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42505"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42506"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42507"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42508"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-43871"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-44503"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-46595"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-46597"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-46598"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-46600"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56852"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56853"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56855"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56858"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56859"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56860"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56862"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-73500"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-78662"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-84304"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-259r-337f-4rfw"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-7j59-v9qr-6fq9"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-cp6g-7hqx-qxhp"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-hrxh-6v49-42gf"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-j88v-2chj-qfwx"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-p77j-4mvh-x3m3"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-pjcq-xvwq-hhpj"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-wf45-q9ch-q8gh"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-xmrv-pmrh-hhx2"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-2303"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25680"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25681"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27136"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27145"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32280"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32281"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32282"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32283"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32288"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32289"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32952"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33186"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33810"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33811"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33814"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33816"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33818"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-34040"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-34986"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39817"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39819"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39820"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39821"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39822"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39823"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39824"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39825"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39826"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39827"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39828"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39829"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39830"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39831"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39832"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39833"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39834"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39835"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39836"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39883"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41178"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41602"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41889"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42499"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42501"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42502"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42504"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42505"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42506"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42507"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42508"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-43871"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-44503"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46595"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46597"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46598"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46600"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56852"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56853"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56855"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56858"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56859"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56860"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56862"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-73500"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78662"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84304"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "severity": [
        {
          "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "type": "CVSS_V3"
        }
      ],
      "summary": "Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection",
      "upstream": [
        "CVE-2026-2303",
        "CVE-2026-25680",
        "CVE-2026-25681",
        "CVE-2026-27136",
        "CVE-2026-27145",
        "CVE-2026-32280",
        "CVE-2026-32281",
        "CVE-2026-32282",
        "CVE-2026-32283",
        "CVE-2026-32288",
        "CVE-2026-32289",
        "CVE-2026-32952",
        "CVE-2026-33186",
        "CVE-2026-33810",
        "CVE-2026-33811",
        "CVE-2026-33814",
        "CVE-2026-33816",
        "CVE-2026-33818",
        "CVE-2026-34040",
        "CVE-2026-34986",
        "CVE-2026-39817",
        "CVE-2026-39819",
        "CVE-2026-39820",
        "CVE-2026-39821",
        "CVE-2026-39822",
        "CVE-2026-39823",
        "CVE-2026-39824",
        "CVE-2026-39825",
        "CVE-2026-39826",
        "CVE-2026-39827",
        "CVE-2026-39828",
        "CVE-2026-39829",
        "CVE-2026-39830",
        "CVE-2026-39831",
        "CVE-2026-39832",
        "CVE-2026-39833",
        "CVE-2026-39834",
        "CVE-2026-39835",
        "CVE-2026-39836",
        "CVE-2026-39883",
        "CVE-2026-41178",
        "CVE-2026-41602",
        "CVE-2026-41889",
        "CVE-2026-42499",
        "CVE-2026-42501",
        "CVE-2026-42502",
        "CVE-2026-42504",
        "CVE-2026-42505",
        "CVE-2026-42506",
        "CVE-2026-42507",
        "CVE-2026-42508",
        "CVE-2026-43871",
        "CVE-2026-44503",
        "CVE-2026-46595",
        "CVE-2026-46597",
        "CVE-2026-46598",
        "CVE-2026-46600",
        "CVE-2026-56852",
        "CVE-2026-56853",
        "CVE-2026-56855",
        "CVE-2026-56858",
        "CVE-2026-56859",
        "CVE-2026-56860",
        "CVE-2026-56862",
        "CVE-2026-73500",
        "CVE-2026-78662",
        "CVE-2026-84304",
        "ghsa-259r-337f-4rfw",
        "ghsa-7j59-v9qr-6fq9",
        "ghsa-cp6g-7hqx-qxhp",
        "ghsa-hrxh-6v49-42gf",
        "ghsa-j88v-2chj-qfwx",
        "ghsa-p77j-4mvh-x3m3",
        "ghsa-pjcq-xvwq-hhpj",
        "ghsa-wf45-q9ch-q8gh",
        "ghsa-xmrv-pmrh-hhx2"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-UJ78067 (CVE-2025-22868)

    Vulnerability from cleanstart – Published: 2026-09-10 02:56 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label
    Details

    Multiple security vulnerabilities affect the stakater-reloader package. The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. See references for individual vulnerability details.

    References
    https://github.com/cleanstart-dev/cleanstart-secu… ADVISORY
    https://osv.dev/vulnerability/CVE-2025-22868 WEB
    https://osv.dev/vulnerability/CVE-2025-47911 WEB
    https://osv.dev/vulnerability/CVE-2025-47912 WEB
    https://osv.dev/vulnerability/CVE-2025-58183 WEB
    https://osv.dev/vulnerability/CVE-2025-58185 WEB
    https://osv.dev/vulnerability/CVE-2025-58186 WEB
    https://osv.dev/vulnerability/CVE-2025-58187 WEB
    https://osv.dev/vulnerability/CVE-2025-58188 WEB
    https://osv.dev/vulnerability/CVE-2025-58189 WEB
    https://osv.dev/vulnerability/CVE-2025-58190 WEB
    https://osv.dev/vulnerability/CVE-2025-61723 WEB
    https://osv.dev/vulnerability/CVE-2025-61724 WEB
    https://osv.dev/vulnerability/CVE-2025-61725 WEB
    https://osv.dev/vulnerability/CVE-2025-61729 WEB
    https://osv.dev/vulnerability/CVE-2026-25679 WEB
    https://osv.dev/vulnerability/CVE-2026-27137 WEB
    https://osv.dev/vulnerability/CVE-2026-27138 WEB
    https://osv.dev/vulnerability/CVE-2026-27139 WEB
    https://osv.dev/vulnerability/CVE-2026-27142 WEB
    https://osv.dev/vulnerability/CVE-2026-33811 WEB
    https://osv.dev/vulnerability/CVE-2026-33814 WEB
    https://osv.dev/vulnerability/CVE-2026-33818 WEB
    https://osv.dev/vulnerability/CVE-2026-39817 WEB
    https://osv.dev/vulnerability/CVE-2026-39819 WEB
    https://osv.dev/vulnerability/CVE-2026-39820 WEB
    https://osv.dev/vulnerability/CVE-2026-39821 WEB
    https://osv.dev/vulnerability/CVE-2026-39822 WEB
    https://osv.dev/vulnerability/CVE-2026-39823 WEB
    https://osv.dev/vulnerability/CVE-2026-39825 WEB
    https://osv.dev/vulnerability/CVE-2026-39826 WEB
    https://osv.dev/vulnerability/CVE-2026-39836 WEB
    https://osv.dev/vulnerability/CVE-2026-42499 WEB
    https://osv.dev/vulnerability/CVE-2026-42501 WEB
    https://osv.dev/vulnerability/CVE-2026-42505 WEB
    https://osv.dev/vulnerability/CVE-2026-46600 WEB
    https://osv.dev/vulnerability/CVE-2026-56852 WEB
    https://osv.dev/vulnerability/CVE-2026-56853 WEB
    https://osv.dev/vulnerability/CVE-2026-56858 WEB
    https://osv.dev/vulnerability/CVE-2026-56859 WEB
    https://osv.dev/vulnerability/CVE-2026-56860 WEB
    https://osv.dev/vulnerability/CVE-2026-56862 WEB
    https://osv.dev/vulnerability/ghsa-259r-337f-4rfw WEB
    https://osv.dev/vulnerability/ghsa-6v2p-p543-phr9 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-22868 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-47911 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-47912 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-58183 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-58185 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-58186 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-58187 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-58188 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-58189 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-58190 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-61723 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-61724 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-61725 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-61729 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-25679 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-27137 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-27138 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-27139 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-27142 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-33811 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-33814 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-33818 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39817 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39819 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39820 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39821 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39822 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39823 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39825 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39826 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39836 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42499 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42501 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42505 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-46600 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56852 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56853 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56858 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56859 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56860 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56862 WEB

    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "stakater-reloader"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "1.4.8-r0"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Multiple security vulnerabilities affect the stakater-reloader package. The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. See references for individual vulnerability details.",
      "id": "CLEANSTART-2026-UJ78067",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-09-10T02:56:12.067685Z",
      "references": [
        {
          "type": "ADVISORY",
          "url": "https://github.com/cleanstart-dev/cleanstart-security-advisories/tree/main/advisories/2026/CLEANSTART-2026-UJ78067.json"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-22868"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-47911"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-47912"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-58183"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-58185"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-58186"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-58187"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-58188"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-58189"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-58190"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-61723"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-61724"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-61725"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-61729"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-25679"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-27137"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-27138"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-27139"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-27142"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-33811"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-33814"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-33818"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39817"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39819"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39820"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39821"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39822"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39823"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39825"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39826"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39836"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42499"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42501"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42505"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-46600"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56852"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56853"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56858"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56859"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56860"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56862"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-259r-337f-4rfw"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-6v2p-p543-phr9"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22868"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47911"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47912"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58183"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58185"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58186"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58187"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58188"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58189"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58190"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61723"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61724"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61725"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61729"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25679"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27137"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27138"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27139"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27142"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33811"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33814"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33818"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39817"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39819"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39820"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39821"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39822"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39823"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39825"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39826"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39836"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42499"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42501"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42505"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46600"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56852"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56853"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56858"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56859"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56860"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56862"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "severity": [
        {
          "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "type": "CVSS_V3"
        }
      ],
      "summary": "ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label",
      "upstream": [
        "CVE-2025-22868",
        "CVE-2025-47911",
        "CVE-2025-47912",
        "CVE-2025-58183",
        "CVE-2025-58185",
        "CVE-2025-58186",
        "CVE-2025-58187",
        "CVE-2025-58188",
        "CVE-2025-58189",
        "CVE-2025-58190",
        "CVE-2025-61723",
        "CVE-2025-61724",
        "CVE-2025-61725",
        "CVE-2025-61729",
        "CVE-2026-25679",
        "CVE-2026-27137",
        "CVE-2026-27138",
        "CVE-2026-27139",
        "CVE-2026-27142",
        "CVE-2026-33811",
        "CVE-2026-33814",
        "CVE-2026-33818",
        "CVE-2026-39817",
        "CVE-2026-39819",
        "CVE-2026-39820",
        "CVE-2026-39821",
        "CVE-2026-39822",
        "CVE-2026-39823",
        "CVE-2026-39825",
        "CVE-2026-39826",
        "CVE-2026-39836",
        "CVE-2026-42499",
        "CVE-2026-42501",
        "CVE-2026-42505",
        "CVE-2026-46600",
        "CVE-2026-56852",
        "CVE-2026-56853",
        "CVE-2026-56858",
        "CVE-2026-56859",
        "CVE-2026-56860",
        "CVE-2026-56862",
        "ghsa-259r-337f-4rfw",
        "ghsa-6v2p-p543-phr9"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-UN51807 (CVE-2026-33818)

    Vulnerability from cleanstart – Published: 2026-09-10 03:01 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI

    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "nats-streaming"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "0.25.6-r6"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Multiple security vulnerabilities affect the nats-streaming package. The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. See references for individual vulnerability details.",
      "id": "CLEANSTART-2026-UN51807",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-09-10T03:01:11.904847Z",
      "references": [
        {
          "type": "ADVISORY",
          "url": "https://github.com/cleanstart-dev/cleanstart-security-advisories/tree/main/advisories/2026/CLEANSTART-2026-UN51807.json"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-33818"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39821"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39822"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42504"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42505"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-46600"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56853"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56858"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-259r-337f-4rfw"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33818"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39821"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39822"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42504"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42505"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46600"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56853"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56858"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "severity": [
        {
          "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "type": "CVSS_V3"
        }
      ],
      "summary": "ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label",
      "upstream": [
        "CVE-2026-33818",
        "CVE-2026-39821",
        "CVE-2026-39822",
        "CVE-2026-42504",
        "CVE-2026-42505",
        "CVE-2026-46600",
        "CVE-2026-56853",
        "CVE-2026-56858",
        "ghsa-259r-337f-4rfw"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-UN57664 (CVE-2026-2303)

    Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    Security fixes in karma 0.131-r1
    Details

    Package karma version 0.131-r1 fixes 6 vulnerabilities: CVE-2026-2303, CVE-2026-39824, ghsa-259r-337f-4rfw, ghsa-3fxj-6jh8-hvhx, ghsa-9g5q-2w5x-hmxf...

    References

    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "karma"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "0.131-r1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "0.131-r1"
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Package karma version 0.131-r1 fixes 6 vulnerabilities: CVE-2026-2303, CVE-2026-39824, ghsa-259r-337f-4rfw, ghsa-3fxj-6jh8-hvhx, ghsa-9g5q-2w5x-hmxf...",
      "id": "CLEANSTART-2026-UN57664",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-09-01T11:17:16Z",
      "references": [
        {
          "type": "WEB",
          "url": "https://github.com/prymitive/karma.git"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "summary": "Security fixes in karma 0.131-r1",
      "upstream": [
        "CVE-2026-2303",
        "CVE-2026-39824",
        "ghsa-259r-337f-4rfw",
        "ghsa-3fxj-6jh8-hvhx",
        "ghsa-9g5q-2w5x-hmxf",
        "ghsa-rjr7-jggh-pgcp"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-UW32521 (GHSA-259R-337F-4RFW)

    Vulnerability from cleanstart – Published: 2026-09-18 09:53 – Updated: 2026-07-31 04:15 – Source website
    VLAI
    Summary
    Security fix for ghsa-259r-337f-4rfw applied in: amazon-cloudwatch-agent 1.300070.0-r1, amazon-cloudwatch-agent 1.300071.0-r1, argo-cd 3.1.16-r4, argo-cd 3.2.12-r3, argo-cd 3.3.12-r4, argo-cd 3.3.14-r2, argo-cd 3.4.5-r2, argo-cd 3.4.6-r0, argo-cd 3.4.7-r2, argo-cd-fips 3.4.7-r1, argo-workflows 3.7.17-r2, cadvisor 0.55.1-r4, cadvisor 0.56.2-r2, cadvisor 0.57.0-r4, cadvisor 0.60.5-r0, calico 3.30.7-r6, cert-manager 1.17.4-r5, cert-manager 1.18.6-r4, cortex 1.18.1-r4, cortex 1.19.1-r2, cortex 1.20.1-r3, cosign 3.1.2-r1, crossplane 2.3.4-r2, dex 2.42.1-r2, dynatrace-operator 1.8.1-r6, dynatrace-operator 1.9.0-r4, elastic-beats 9.1.10-r5, elastic-beats 9.2.8-r7, elastic-beats 9.3.7-r1, elastic-beats 9.3.9-r0, elastic-beats 9.4.2-r3, flux-notification-controller-fips 1.9.2-r0, fulcio-fips 1.6.6-r3, gitea 1.26.4-r1, gitea 1.27.0-r2, gitea 1.27.2-r1, grafana 12.3.10-r1, grafana 12.3.8-r2, grafana 12.4.5-r2, grafana 12.4.6-r0, grafana 12.4.7-r1, grafana 12.4.9-r1, grafana 13.0.5-r1, grafana 13.0.7-r1, haproxy-ingress 0.14.12-r2, helm-operator 1.39.2-r1, helm-operator 1.40.0-r1, istio 1.29.6-r2, karma 0.128-r1, karma 0.129-r1, karma 0.130-r1, karma 0.131-r1, knative-net-istio 1.21.4-r2, knative-serving 1.20.3-r0, kube-metrics-adapter 0.2.9-r1, kubernetes-dns-node-cache 1.23.1-r1, kubernetes-dns-node-cache 1.24.1-r2, kubernetes-dns-node-cache 1.25.0-r9, kubernetes-dns-node-cache 1.26.8-r6, kubernetes-event-exporter 1.5-r3, kyverno 1.16.4-r3, kyverno 1.17.2-r2, kyverno 1.18.1-r3, local-path-provisioner-fips 0.0.36-r1, logstash-exporter 1.7.1-r1, logstash-exporter 1.8.4-r1, loki 3.6.12-r2, minio-operator 6.0.4-r6, minio-operator 7.0.1-r7, mongodb 8.1.3-r3, mongodb 8.3.7-r0, nats-streaming 0.22.1-r1, nats-streaming 0.23.2-r1, nats-streaming 0.24.6-r4, nats-streaming 0.25.6-r5, newrelic-infrastructure-agent 1.76.2-r1, newrelic-infrastructure-agent 1.78.1-r1, newrelic-infrastructure-agent 1.79.0-r1, ollama 0.31.2-r1, ollama 0.32.0-r1, ollama 0.32.11-r3, ollama 0.32.4-r1, ollama 0.32.7-r1, ollama 0.32.9-r1, ollama-fips 0.30.11-r2, ollama-fips 0.32.1-r1, ollama-fips 0.32.11-r2, ollama-fips 0.32.14-r2, ollama-fips 0.32.4-r1, ollama-fips 0.32.7-r1, ollama-fips 0.32.8-r1, ollama-fips 0.32.9-r2, opentelemetry-collector-contrib 0.153.0-r3, opentelemetry-collector-contrib 0.155.0-r1, percona-server-mongodb-operator 1.23.0-r0, policy-controller-fips 0.15.1-r1, prometheus 3.10.0-r7, prometheus 3.11.3-r5, prometheus 3.13.1-r2, prometheus 3.5.3-r6, prometheus 3.9.1-r9, prometheus-alertmanager 0.33.0-r2, prometheus-fips 3.10.0-r1, prometheus-fips 3.11.3-r1, prometheus-fips 3.12.0-r1, prometheus-mysqld-exporter 0.16.0-r4, prometheus-mysqld-exporter 0.17.2-r4, prometheus-pushgateway 1.10.0-r3, prometheus-redis-exporter 1.85.0-r1, prometheus-redis-exporter 1.86.0-r1, prometheus-redis-exporter 1.88.0-r2, prometheus-redis-exporter-fips 1.87.0-r1, prometheus-statsd-exporter 0.27.2-r1, prometheus-statsd-exporter 0.28.0-r3, pulumi 3.248.0-r0, rabbitmq-messaging-topology-operator 1.16.0-r2, rancher-agent 2.11.15-r1, rancher-agent 2.12.11-r1, rancher-agent 2.13.7-r3, rancher-agent 2.14.3-r0, rancher-fleet-agent 0.12.17-r1, rancher-fleet-agent 0.14.10-r1, rancher-fleet-agent 0.14.8-r1, rancher-fleet-agent 0.15.4-r1, rancher-fleet-agent 0.15.6-r0, rancher-fleet-agent 0.16.1-r1, rclone 1.71.2-r3, rclone 1.72.1-r11, rclone 1.73.5-r5, rclone 1.74.3-r2, spire-server 1.14.7-r0, stakater-reloader 1.1.0-r3, stakater-reloader 1.2.1-r2, stakater-reloader 1.3.0-r2, step 0.27.5-r3, step 0.28.7-r4, step 0.29.0-r3, step-ca 0.27.5-r0, step-cli 0.27.5-r1, step-cli 0.30.6-r0, step-issuer 0.11.0-r4, step-issuer 0.9.11-r2, tekton-chains 0.25.2-r1, tekton-chains-fips 0.24.0-r1, tekton-chains-fips 0.25.2-r1, tekton-chains-fips 0.26.5-r1, tempo 2.10.7-r2, tempo 2.10.8-r1, tempo 2.9.5-r2, temporal-server 1.28.4-r2, temporal-server 1.29.7-r2, temporal-server 1.30.5-r1, temporal-server 1.30.6-r3, terraform 1.15.7-r0, tigera-operator 1.39.3-r1, tigera-operator 1.40.13-r1, tigera-operator 1.42.1-r2, tigera-operator 1.42.3-r2, tkn 0.42.2-r1, tkn 0.43.2-r1, tkn 0.44.2-r1, tkn 0.45.0-r1, vault 1.19.5-r1, vault 1.20.4-r8, vault 1.21.4-r9, vault 2.0.3-r1, vault-k8s 1.5.0-r2, vault-k8s 1.6.2-r1, velero 1.15.2-r6, velero 1.17.2-r7, velero 1.18.2-r6, victoriametrics-operator 0.71.0-r2, victoriametrics-operator-fips 0.69.0-r0, victoriametrics-operator-fips 0.70.1-r0, victoriametrics-operator-fips 0.71.0-r0, victoriametrics-operator-fips 0.72.0-r1, wave 0.10.0-r4, weaviate-fips 1.37.14-r0, weaviate-fips 1.38.6-r1
    Details

    ghsa-259r-337f-4rfw affects multiple packages. This issue is resolved in later releases. See references for individual vulnerability details.


    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "amazon-cloudwatch-agent"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "1.300070.0-r1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "amazon-cloudwatch-agent"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "1.300071.0-r1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "argo-cd"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "3.1.16-r4"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "argo-cd"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "3.2.12-r3"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "argo-cd"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "3.3.12-r4"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "argo-cd"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "3.3.14-r2"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "argo-cd"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "3.4.5-r2"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "argo-cd"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "3.4.6-r0"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "argo-cd"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "3.4.7-r2"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "argo-cd-fips"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "3.4.7-r1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "argo-workflows"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "3.7.17-r2"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "cadvisor"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "0.55.1-r4"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "cadvisor"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "0.56.2-r2"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "cadvisor"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "0.57.0-r4"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "cadvisor"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "0.60.5-r0"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "calico"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "3.30.7-r6"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "cert-manager"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "1.17.4-r5"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "cert-manager"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "1.18.6-r4"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "cortex"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "1.18.1-r4"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "cortex"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "1.19.1-r2"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "cortex"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "1.20.1-r3"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "cosign"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "3.1.2-r1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "crossplane"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "2.3.4-r2"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "dex"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "2.42.1-r2"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "dynatrace-operator"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "1.8.1-r6"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "dynatrace-operator"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "1.9.0-r4"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "elastic-beats"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "9.1.10-r5"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "elastic-beats"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "9.2.8-r7"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "elastic-beats"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "9.3.7-r1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "elastic-beats"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "9.3.9-r0"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "elastic-beats"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "9.4.2-r3"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "flux-notification-controller-fips"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "1.9.2-r0"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "fulcio-fips"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "1.6.6-r3"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "gitea"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "1.26.4-r1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "gitea"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "1.27.0-r2"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "gitea"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "1.27.2-r1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "grafana"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "12.3.10-r1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "grafana"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "12.3.8-r2"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "grafana"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "12.4.5-r2"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "grafana"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "12.4.6-r0"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "grafana"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "12.4.7-r1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "grafana"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "12.4.9-r1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "grafana"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "13.0.5-r1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "grafana"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "13.0.7-r1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "haproxy-ingress"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "0.14.12-r2"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "helm-operator"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "1.39.2-r1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "helm-operator"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "1.40.0-r1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "istio"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "1.29.6-r2"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "karma"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "0.128-r1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "karma"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "0.129-r1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "karma"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "0.130-r1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "karma"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "0.131-r1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "knative-net-istio"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "1.21.4-r2"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "knative-serving"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "1.20.3-r0"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "kube-metrics-adapter"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "0.2.9-r1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "kubernetes-dns-node-cache"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "1.23.1-r1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "kubernetes-dns-node-cache"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "1.24.1-r2"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "kubernetes-dns-node-cache"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "1.25.0-r9"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "kubernetes-dns-node-cache"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "1.26.8-r6"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "kubernetes-event-exporter"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "1.5-r3"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "kyverno"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "1.16.4-r3"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "kyverno"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "1.17.2-r2"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "kyverno"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "1.18.1-r3"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "local-path-provisioner-fips"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "0.0.36-r1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "logstash-exporter"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "1.7.1-r1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "logstash-exporter"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "1.8.4-r1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "loki"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "3.6.12-r2"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "minio-operator"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "6.0.4-r6"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "minio-operator"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "7.0.1-r7"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "mongodb"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "8.1.3-r3"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "mongodb"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "8.3.7-r0"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "nats-streaming"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "0.22.1-r1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "nats-streaming"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "0.23.2-r1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "nats-streaming"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "0.24.6-r4"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "nats-streaming"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "0.25.6-r5"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "newrelic-infrastructure-agent"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "1.76.2-r1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "newrelic-infrastructure-agent"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "1.78.1-r1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "newrelic-infrastructure-agent"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "1.79.0-r1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "ollama"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "0.31.2-r1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "ollama"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "0.32.0-r1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "ollama"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "0.32.11-r3"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "ollama"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "0.32.4-r1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "ollama"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "0.32.7-r1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "ollama"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "0.32.9-r1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "ollama-fips"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "0.30.11-r2"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "ollama-fips"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "0.32.1-r1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "ollama-fips"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "0.32.11-r2"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "ollama-fips"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "0.32.14-r2"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "ollama-fips"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "0.32.4-r1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "ollama-fips"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "0.32.7-r1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "ollama-fips"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "0.32.8-r1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "ollama-fips"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "0.32.9-r2"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "opentelemetry-collector-contrib"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "0.153.0-r3"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "opentelemetry-collector-contrib"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "0.155.0-r1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "percona-server-mongodb-operator"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "1.23.0-r0"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "policy-controller-fips"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "0.15.1-r1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "prometheus"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "3.10.0-r7"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "prometheus"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "3.11.3-r5"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "prometheus"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "3.13.1-r2"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "prometheus"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "3.5.3-r6"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "prometheus"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "3.9.1-r9"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "prometheus-alertmanager"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "0.33.0-r2"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "prometheus-fips"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "3.10.0-r1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "prometheus-fips"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "3.11.3-r1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "prometheus-fips"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "3.12.0-r1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "prometheus-mysqld-exporter"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "0.16.0-r4"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "prometheus-mysqld-exporter"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "0.17.2-r4"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "prometheus-pushgateway"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "1.10.0-r3"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "prometheus-redis-exporter"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "1.85.0-r1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "prometheus-redis-exporter"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "1.86.0-r1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "prometheus-redis-exporter"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "1.88.0-r2"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "prometheus-redis-exporter-fips"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "1.87.0-r1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "prometheus-statsd-exporter"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "0.27.2-r1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "prometheus-statsd-exporter"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "0.28.0-r3"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "pulumi"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "3.248.0-r0"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "rabbitmq-messaging-topology-operator"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "1.16.0-r2"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "rancher-agent"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "2.11.15-r1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "rancher-agent"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "2.12.11-r1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "rancher-agent"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "2.13.7-r3"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "rancher-agent"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "2.14.3-r0"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "rancher-fleet-agent"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "0.12.17-r1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "rancher-fleet-agent"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "0.14.10-r1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "rancher-fleet-agent"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "0.14.8-r1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "rancher-fleet-agent"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "0.15.4-r1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "rancher-fleet-agent"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "0.15.6-r0"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "rancher-fleet-agent"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "0.16.1-r1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "rclone"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "1.71.2-r3"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "rclone"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "1.72.1-r11"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "rclone"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "1.73.5-r5"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "rclone"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "1.74.3-r2"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "spire-server"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "1.14.7-r0"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "stakater-reloader"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "1.1.0-r3"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "stakater-reloader"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "1.2.1-r2"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "stakater-reloader"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "1.3.0-r2"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "step"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "0.27.5-r3"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "step"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "0.28.7-r4"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "step"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "0.29.0-r3"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "step-ca"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "0.27.5-r0"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "step-cli"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "0.27.5-r1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "step-cli"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "0.30.6-r0"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "step-issuer"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "0.11.0-r4"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "step-issuer"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "0.9.11-r2"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "tekton-chains"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "0.25.2-r1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "tekton-chains-fips"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "0.24.0-r1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "tekton-chains-fips"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "0.25.2-r1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "tekton-chains-fips"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "0.26.5-r1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "tempo"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "2.10.7-r2"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "tempo"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "2.10.8-r1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "tempo"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "2.9.5-r2"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "temporal-server"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "1.28.4-r2"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "temporal-server"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "1.29.7-r2"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "temporal-server"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "1.30.5-r1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "temporal-server"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "1.30.6-r3"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "terraform"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "1.15.7-r0"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "tigera-operator"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "1.39.3-r1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "tigera-operator"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "1.40.13-r1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "tigera-operator"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "1.42.1-r2"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "tigera-operator"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "1.42.3-r2"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "tkn"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "0.42.2-r1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "tkn"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "0.43.2-r1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "tkn"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "0.44.2-r1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "tkn"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "0.45.0-r1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "vault"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "1.19.5-r1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "vault"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "1.20.4-r8"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "vault"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "1.21.4-r9"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "vault"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "2.0.3-r1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "vault-k8s"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "1.5.0-r2"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "vault-k8s"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "1.6.2-r1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "velero"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "1.15.2-r6"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "velero"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "1.17.2-r7"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "velero"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "1.18.2-r6"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "victoriametrics-operator"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "0.71.0-r2"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "victoriametrics-operator-fips"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "0.69.0-r0"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "victoriametrics-operator-fips"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "0.70.1-r0"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "victoriametrics-operator-fips"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "0.71.0-r0"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "victoriametrics-operator-fips"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "0.72.0-r1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "wave"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "0.10.0-r4"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "weaviate-fips"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "1.37.14-r0"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "weaviate-fips"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "1.38.6-r1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "ghsa-259r-337f-4rfw affects multiple packages. This issue is resolved in later releases. See references for individual vulnerability details.",
      "id": "CLEANSTART-2026-UW32521",
      "modified": "2026-07-31T04:15:06Z",
      "published": "2026-09-18T09:53:24.548311Z",
      "references": [
        {
          "type": "ADVISORY",
          "url": "https://github.com/cleanstart-dev/cleanstart-security-advisories/tree/main/advisories/2026/CLEANSTART-2026-UW32521.json"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-259r-337f-4rfw"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "summary": "Security fix for ghsa-259r-337f-4rfw applied in: amazon-cloudwatch-agent 1.300070.0-r1, amazon-cloudwatch-agent 1.300071.0-r1, argo-cd 3.1.16-r4, argo-cd 3.2.12-r3, argo-cd 3.3.12-r4, argo-cd 3.3.14-r2, argo-cd 3.4.5-r2, argo-cd 3.4.6-r0, argo-cd 3.4.7-r2, argo-cd-fips 3.4.7-r1, argo-workflows 3.7.17-r2, cadvisor 0.55.1-r4, cadvisor 0.56.2-r2, cadvisor 0.57.0-r4, cadvisor 0.60.5-r0, calico 3.30.7-r6, cert-manager 1.17.4-r5, cert-manager 1.18.6-r4, cortex 1.18.1-r4, cortex 1.19.1-r2, cortex 1.20.1-r3, cosign 3.1.2-r1, crossplane 2.3.4-r2, dex 2.42.1-r2, dynatrace-operator 1.8.1-r6, dynatrace-operator 1.9.0-r4, elastic-beats 9.1.10-r5, elastic-beats 9.2.8-r7, elastic-beats 9.3.7-r1, elastic-beats 9.3.9-r0, elastic-beats 9.4.2-r3, flux-notification-controller-fips 1.9.2-r0, fulcio-fips 1.6.6-r3, gitea 1.26.4-r1, gitea 1.27.0-r2, gitea 1.27.2-r1, grafana 12.3.10-r1, grafana 12.3.8-r2, grafana 12.4.5-r2, grafana 12.4.6-r0, grafana 12.4.7-r1, grafana 12.4.9-r1, grafana 13.0.5-r1, grafana 13.0.7-r1, haproxy-ingress 0.14.12-r2, helm-operator 1.39.2-r1, helm-operator 1.40.0-r1, istio 1.29.6-r2, karma 0.128-r1, karma 0.129-r1, karma 0.130-r1, karma 0.131-r1, knative-net-istio 1.21.4-r2, knative-serving 1.20.3-r0, kube-metrics-adapter 0.2.9-r1, kubernetes-dns-node-cache 1.23.1-r1, kubernetes-dns-node-cache 1.24.1-r2, kubernetes-dns-node-cache 1.25.0-r9, kubernetes-dns-node-cache 1.26.8-r6, kubernetes-event-exporter 1.5-r3, kyverno 1.16.4-r3, kyverno 1.17.2-r2, kyverno 1.18.1-r3, local-path-provisioner-fips 0.0.36-r1, logstash-exporter 1.7.1-r1, logstash-exporter 1.8.4-r1, loki 3.6.12-r2, minio-operator 6.0.4-r6, minio-operator 7.0.1-r7, mongodb 8.1.3-r3, mongodb 8.3.7-r0, nats-streaming 0.22.1-r1, nats-streaming 0.23.2-r1, nats-streaming 0.24.6-r4, nats-streaming 0.25.6-r5, newrelic-infrastructure-agent 1.76.2-r1, newrelic-infrastructure-agent 1.78.1-r1, newrelic-infrastructure-agent 1.79.0-r1, ollama 0.31.2-r1, ollama 0.32.0-r1, ollama 0.32.11-r3, ollama 0.32.4-r1, ollama 0.32.7-r1, ollama 0.32.9-r1, ollama-fips 0.30.11-r2, ollama-fips 0.32.1-r1, ollama-fips 0.32.11-r2, ollama-fips 0.32.14-r2, ollama-fips 0.32.4-r1, ollama-fips 0.32.7-r1, ollama-fips 0.32.8-r1, ollama-fips 0.32.9-r2, opentelemetry-collector-contrib 0.153.0-r3, opentelemetry-collector-contrib 0.155.0-r1, percona-server-mongodb-operator 1.23.0-r0, policy-controller-fips 0.15.1-r1, prometheus 3.10.0-r7, prometheus 3.11.3-r5, prometheus 3.13.1-r2, prometheus 3.5.3-r6, prometheus 3.9.1-r9, prometheus-alertmanager 0.33.0-r2, prometheus-fips 3.10.0-r1, prometheus-fips 3.11.3-r1, prometheus-fips 3.12.0-r1, prometheus-mysqld-exporter 0.16.0-r4, prometheus-mysqld-exporter 0.17.2-r4, prometheus-pushgateway 1.10.0-r3, prometheus-redis-exporter 1.85.0-r1, prometheus-redis-exporter 1.86.0-r1, prometheus-redis-exporter 1.88.0-r2, prometheus-redis-exporter-fips 1.87.0-r1, prometheus-statsd-exporter 0.27.2-r1, prometheus-statsd-exporter 0.28.0-r3, pulumi 3.248.0-r0, rabbitmq-messaging-topology-operator 1.16.0-r2, rancher-agent 2.11.15-r1, rancher-agent 2.12.11-r1, rancher-agent 2.13.7-r3, rancher-agent 2.14.3-r0, rancher-fleet-agent 0.12.17-r1, rancher-fleet-agent 0.14.10-r1, rancher-fleet-agent 0.14.8-r1, rancher-fleet-agent 0.15.4-r1, rancher-fleet-agent 0.15.6-r0, rancher-fleet-agent 0.16.1-r1, rclone 1.71.2-r3, rclone 1.72.1-r11, rclone 1.73.5-r5, rclone 1.74.3-r2, spire-server 1.14.7-r0, stakater-reloader 1.1.0-r3, stakater-reloader 1.2.1-r2, stakater-reloader 1.3.0-r2, step 0.27.5-r3, step 0.28.7-r4, step 0.29.0-r3, step-ca 0.27.5-r0, step-cli 0.27.5-r1, step-cli 0.30.6-r0, step-issuer 0.11.0-r4, step-issuer 0.9.11-r2, tekton-chains 0.25.2-r1, tekton-chains-fips 0.24.0-r1, tekton-chains-fips 0.25.2-r1, tekton-chains-fips 0.26.5-r1, tempo 2.10.7-r2, tempo 2.10.8-r1, tempo 2.9.5-r2, temporal-server 1.28.4-r2, temporal-server 1.29.7-r2, temporal-server 1.30.5-r1, temporal-server 1.30.6-r3, terraform 1.15.7-r0, tigera-operator 1.39.3-r1, tigera-operator 1.40.13-r1, tigera-operator 1.42.1-r2, tigera-operator 1.42.3-r2, tkn 0.42.2-r1, tkn 0.43.2-r1, tkn 0.44.2-r1, tkn 0.45.0-r1, vault 1.19.5-r1, vault 1.20.4-r8, vault 1.21.4-r9, vault 2.0.3-r1, vault-k8s 1.5.0-r2, vault-k8s 1.6.2-r1, velero 1.15.2-r6, velero 1.17.2-r7, velero 1.18.2-r6, victoriametrics-operator 0.71.0-r2, victoriametrics-operator-fips 0.69.0-r0, victoriametrics-operator-fips 0.70.1-r0, victoriametrics-operator-fips 0.71.0-r0, victoriametrics-operator-fips 0.72.0-r1, wave 0.10.0-r4, weaviate-fips 1.37.14-r0, weaviate-fips 1.38.6-r1",
      "upstream": [
        "ghsa-259r-337f-4rfw"
      ]
    }

    CLEANSTART-2026-UW93671 (GHSA-259R-337F-4RFW)

    Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    Security fixes in prometheus-redis-exporter 1.88.0-r2
    Details

    Package prometheus-redis-exporter version 1.88.0-r2 fixes 1 vulnerabilities: ghsa-259r-337f-4rfw


    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "prometheus-redis-exporter"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "1.88.0-r2"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "1.88.0-r2"
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Package prometheus-redis-exporter version 1.88.0-r2 fixes 1 vulnerabilities: ghsa-259r-337f-4rfw",
      "id": "CLEANSTART-2026-UW93671",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-09-01T11:17:16Z",
      "references": [
        {
          "type": "WEB",
          "url": "https://github.com/oliver006/redis_exporter"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "summary": "Security fixes in prometheus-redis-exporter 1.88.0-r2",
      "upstream": [
        "ghsa-259r-337f-4rfw"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-UZ65030 (CVE-2026-33818)

    Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    Security fixes in tkn 0.44.2-r1
    Details

    Package tkn version 0.44.2-r1 fixes 27 vulnerabilities: CVE-2026-33818, CVE-2026-56853, CVE-2026-56858, CVE-2026-56859, CVE-2026-56860...

    References

    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "tkn"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "0.44.2-r1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "0.44.2-r1"
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Package tkn version 0.44.2-r1 fixes 27 vulnerabilities: CVE-2026-33818, CVE-2026-56853, CVE-2026-56858, CVE-2026-56859, CVE-2026-56860...",
      "id": "CLEANSTART-2026-UZ65030",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-09-01T11:17:16Z",
      "references": [
        {
          "type": "WEB",
          "url": "https://github.com/tektoncd/cli"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "summary": "Security fixes in tkn 0.44.2-r1",
      "upstream": [
        "CVE-2026-33818",
        "CVE-2026-56853",
        "CVE-2026-56858",
        "CVE-2026-56859",
        "CVE-2026-56860",
        "CVE-2026-56862",
        "CVE-2026-39821",
        "CVE-2026-34040",
        "CVE-2026-33997",
        "ghsa-gcjh-h69q-9w9g",
        "ghsa-pmwq-pjrm-6p5r",
        "CVE-2026-49478",
        "CVE-2026-48702",
        "CVE-2026-49834",
        "CVE-2026-54787",
        "CVE-2026-39984",
        "CVE-2026-49835",
        "CVE-2026-2303",
        "CVE-2026-46600",
        "CVE-2026-56852",
        "ghsa-hrxh-6v49-42gf",
        "CVE-2026-56864",
        "CVE-2026-56865",
        "ghsa-259r-337f-4rfw",
        "ghsa-3fxj-6jh8-hvhx",
        "ghsa-9g5q-2w5x-hmxf",
        "ghsa-rjr7-jggh-pgcp"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-VB09315 (CVE-2026-33186)

    Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    Security fixes in rancher-fleet-agent 0.12.17-r1
    Details

    Package rancher-fleet-agent version 0.12.17-r1 fixes 40 vulnerabilities: CVE-2026-33186, ghsa-hrxh-6v49-42gf, CVE-2026-46680, CVE-2026-53488, CVE-2026-47262...

    References

    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "rancher-fleet-agent"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "0.12.17-r1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "0.12.17-r1"
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Package rancher-fleet-agent version 0.12.17-r1 fixes 40 vulnerabilities: CVE-2026-33186, ghsa-hrxh-6v49-42gf, CVE-2026-46680, CVE-2026-53488, CVE-2026-47262...",
      "id": "CLEANSTART-2026-VB09315",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-09-01T11:17:16Z",
      "references": [
        {
          "type": "WEB",
          "url": "https://github.com/rancher/fleet"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "summary": "Security fixes in rancher-fleet-agent 0.12.17-r1",
      "upstream": [
        "CVE-2026-33186",
        "ghsa-hrxh-6v49-42gf",
        "CVE-2026-46680",
        "CVE-2026-53488",
        "CVE-2026-47262",
        "CVE-2026-50195",
        "CVE-2026-53492",
        "CVE-2026-53489",
        "CVE-2026-39835",
        "CVE-2026-39828",
        "CVE-2026-39829",
        "CVE-2026-46597",
        "CVE-2026-39830",
        "CVE-2026-39831",
        "CVE-2026-39832",
        "CVE-2026-39833",
        "CVE-2026-39834",
        "CVE-2026-42508",
        "CVE-2026-46595",
        "CVE-2026-46598",
        "CVE-2026-39827",
        "CVE-2026-25681",
        "CVE-2026-27136",
        "CVE-2026-39821",
        "CVE-2026-42502",
        "CVE-2026-42506",
        "CVE-2026-25680",
        "CVE-2026-33814",
        "CVE-2026-46600",
        "CVE-2026-29181",
        "CVE-2026-35469",
        "CVE-2026-56852",
        "CVE-2026-50163",
        "CVE-2026-50151",
        "CVE-2026-50162",
        "ghsa-vh4v-2xq2-g5cg",
        "CVE-2026-48978",
        "CVE-2026-35206",
        "ghsa-259r-337f-4rfw",
        "CVE-2026-39824"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-VD81951 (CVE-2026-41178)

    Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    Security fixes in fulcio-fips 1.6.6-r3
    Details

    Package fulcio-fips version 1.6.6-r3 fixes 7 vulnerabilities: CVE-2026-41178, ghsa-hrxh-6v49-42gf, ghsa-259r-337f-4rfw, CVE-2026-24137, CVE-2026-39821...

    References

    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "fulcio-fips"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "1.6.6-r3"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "1.6.6-r3"
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Package fulcio-fips version 1.6.6-r3 fixes 7 vulnerabilities: CVE-2026-41178, ghsa-hrxh-6v49-42gf, ghsa-259r-337f-4rfw, CVE-2026-24137, CVE-2026-39821...",
      "id": "CLEANSTART-2026-VD81951",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-09-01T11:17:16Z",
      "references": [
        {
          "type": "WEB",
          "url": "https://github.com/sigstore/fulcio"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "summary": "Security fixes in fulcio-fips 1.6.6-r3",
      "upstream": [
        "CVE-2026-41178",
        "ghsa-hrxh-6v49-42gf",
        "ghsa-259r-337f-4rfw",
        "CVE-2026-24137",
        "CVE-2026-39821",
        "CVE-2026-46600",
        "CVE-2026-33186"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-VI74714 (GHSA-R277-6W6Q-XMQW)

    Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    Security fixes in grafana 13.0.5-r1
    Details

    Package grafana version 13.0.5-r1 fixes 8 vulnerabilities: ghsa-r277-6w6q-xmqw, ghsa-jpcw-4wr7-c3vq, CVE-2026-21728, CVE-2026-28377, CVE-2026-42151...

    References

    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "grafana"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "13.0.5-r1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "13.0.5-r1"
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Package grafana version 13.0.5-r1 fixes 8 vulnerabilities: ghsa-r277-6w6q-xmqw, ghsa-jpcw-4wr7-c3vq, CVE-2026-21728, CVE-2026-28377, CVE-2026-42151...",
      "id": "CLEANSTART-2026-VI74714",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-09-01T11:17:16Z",
      "references": [
        {
          "type": "WEB",
          "url": "https://grafana.com"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "summary": "Security fixes in grafana 13.0.5-r1",
      "upstream": [
        "ghsa-r277-6w6q-xmqw",
        "ghsa-jpcw-4wr7-c3vq",
        "CVE-2026-21728",
        "CVE-2026-28377",
        "CVE-2026-42151",
        "CVE-2026-40179",
        "CVE-2026-44903",
        "ghsa-259r-337f-4rfw"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-VK86621 (CVE-2026-39821)

    Vulnerability from cleanstart – Published: 2026-09-18 01:13 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for CVE-2...
    Details

    Multiple security vulnerabilities affect the dynatrace-operator package. The source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for CVE-2026-46595. See references for individual vulnerability details.


    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "dynatrace-operator"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "1.9.0-r6"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Multiple security vulnerabilities affect the dynatrace-operator package. The source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for CVE-2026-46595. See references for individual vulnerability details.",
      "id": "CLEANSTART-2026-VK86621",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-09-18T01:13:28.670790Z",
      "references": [
        {
          "type": "ADVISORY",
          "url": "https://github.com/cleanstart-dev/cleanstart-security-advisories/tree/main/advisories/2026/CLEANSTART-2026-VK86621.json"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39821"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-41178"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-46600"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56854"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56855"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56859"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56860"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56864"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-78662"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-84303"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-84304"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-84445"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-259r-337f-4rfw"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39821"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41178"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46600"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56854"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56855"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56859"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56860"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56864"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78662"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84303"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84304"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84445"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "severity": [
        {
          "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "type": "CVSS_V3"
        }
      ],
      "summary": "source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for CVE-2...",
      "upstream": [
        "CVE-2026-39821",
        "CVE-2026-41178",
        "CVE-2026-46600",
        "CVE-2026-56854",
        "CVE-2026-56855",
        "CVE-2026-56859",
        "CVE-2026-56860",
        "CVE-2026-56864",
        "CVE-2026-78662",
        "CVE-2026-84303",
        "CVE-2026-84304",
        "CVE-2026-84445",
        "ghsa-259r-337f-4rfw"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-VO98287 (CVE-2025-63811)

    Vulnerability from cleanstart – Published: 2026-09-10 02:48 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection
    Details

    Multiple security vulnerabilities affect the vault package. Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. See references for individual vulnerability details.

    References
    https://github.com/cleanstart-dev/cleanstart-secu… ADVISORY
    https://osv.dev/vulnerability/CVE-2025-63811 WEB
    https://osv.dev/vulnerability/CVE-2026-1229 WEB
    https://osv.dev/vulnerability/CVE-2026-2303 WEB
    https://osv.dev/vulnerability/CVE-2026-24051 WEB
    https://osv.dev/vulnerability/CVE-2026-25680 WEB
    https://osv.dev/vulnerability/CVE-2026-25681 WEB
    https://osv.dev/vulnerability/CVE-2026-26958 WEB
    https://osv.dev/vulnerability/CVE-2026-27136 WEB
    https://osv.dev/vulnerability/CVE-2026-27145 WEB
    https://osv.dev/vulnerability/CVE-2026-32280 WEB
    https://osv.dev/vulnerability/CVE-2026-32281 WEB
    https://osv.dev/vulnerability/CVE-2026-32282 WEB
    https://osv.dev/vulnerability/CVE-2026-32283 WEB
    https://osv.dev/vulnerability/CVE-2026-32288 WEB
    https://osv.dev/vulnerability/CVE-2026-32289 WEB
    https://osv.dev/vulnerability/CVE-2026-32952 WEB
    https://osv.dev/vulnerability/CVE-2026-33186 WEB
    https://osv.dev/vulnerability/CVE-2026-33810 WEB
    https://osv.dev/vulnerability/CVE-2026-33811 WEB
    https://osv.dev/vulnerability/CVE-2026-33814 WEB
    https://osv.dev/vulnerability/CVE-2026-33816 WEB
    https://osv.dev/vulnerability/CVE-2026-33818 WEB
    https://osv.dev/vulnerability/CVE-2026-34986 WEB
    https://osv.dev/vulnerability/CVE-2026-39817 WEB
    https://osv.dev/vulnerability/CVE-2026-39819 WEB
    https://osv.dev/vulnerability/CVE-2026-39820 WEB
    https://osv.dev/vulnerability/CVE-2026-39821 WEB
    https://osv.dev/vulnerability/CVE-2026-39822 WEB
    https://osv.dev/vulnerability/CVE-2026-39823 WEB
    https://osv.dev/vulnerability/CVE-2026-39824 WEB
    https://osv.dev/vulnerability/CVE-2026-39825 WEB
    https://osv.dev/vulnerability/CVE-2026-39826 WEB
    https://osv.dev/vulnerability/CVE-2026-39827 WEB
    https://osv.dev/vulnerability/CVE-2026-39828 WEB
    https://osv.dev/vulnerability/CVE-2026-39829 WEB
    https://osv.dev/vulnerability/CVE-2026-39830 WEB
    https://osv.dev/vulnerability/CVE-2026-39831 WEB
    https://osv.dev/vulnerability/CVE-2026-39832 WEB
    https://osv.dev/vulnerability/CVE-2026-39833 WEB
    https://osv.dev/vulnerability/CVE-2026-39834 WEB
    https://osv.dev/vulnerability/CVE-2026-39835 WEB
    https://osv.dev/vulnerability/CVE-2026-39836 WEB
    https://osv.dev/vulnerability/CVE-2026-39883 WEB
    https://osv.dev/vulnerability/CVE-2026-41178 WEB
    https://osv.dev/vulnerability/CVE-2026-41602 WEB
    https://osv.dev/vulnerability/CVE-2026-41889 WEB
    https://osv.dev/vulnerability/CVE-2026-42499 WEB
    https://osv.dev/vulnerability/CVE-2026-42501 WEB
    https://osv.dev/vulnerability/CVE-2026-42502 WEB
    https://osv.dev/vulnerability/CVE-2026-42504 WEB
    https://osv.dev/vulnerability/CVE-2026-42505 WEB
    https://osv.dev/vulnerability/CVE-2026-42506 WEB
    https://osv.dev/vulnerability/CVE-2026-42507 WEB
    https://osv.dev/vulnerability/CVE-2026-42508 WEB
    https://osv.dev/vulnerability/CVE-2026-44503 WEB
    https://osv.dev/vulnerability/CVE-2026-46595 WEB
    https://osv.dev/vulnerability/CVE-2026-46597 WEB
    https://osv.dev/vulnerability/CVE-2026-46598 WEB
    https://osv.dev/vulnerability/CVE-2026-46600 WEB
    https://osv.dev/vulnerability/CVE-2026-56852 WEB
    https://osv.dev/vulnerability/CVE-2026-56853 WEB
    https://osv.dev/vulnerability/CVE-2026-56854 WEB
    https://osv.dev/vulnerability/CVE-2026-56855 WEB
    https://osv.dev/vulnerability/CVE-2026-56858 WEB
    https://osv.dev/vulnerability/CVE-2026-56859 WEB
    https://osv.dev/vulnerability/CVE-2026-56860 WEB
    https://osv.dev/vulnerability/CVE-2026-56862 WEB
    https://osv.dev/vulnerability/CVE-2026-73500 WEB
    https://osv.dev/vulnerability/CVE-2026-78662 WEB
    https://osv.dev/vulnerability/CVE-2026-84304 WEB
    https://osv.dev/vulnerability/ghsa-259r-337f-4rfw WEB
    https://osv.dev/vulnerability/ghsa-78h2-9frx-2jm8 WEB
    https://osv.dev/vulnerability/ghsa-7j59-v9qr-6fq9 WEB
    https://osv.dev/vulnerability/ghsa-cp6g-7hqx-qxhp WEB
    https://osv.dev/vulnerability/ghsa-j88v-2chj-qfwx WEB
    https://osv.dev/vulnerability/ghsa-p77j-4mvh-x3m3 WEB
    https://osv.dev/vulnerability/ghsa-pjcq-xvwq-hhpj WEB
    https://osv.dev/vulnerability/ghsa-w67g-5rqw-f597 WEB
    https://osv.dev/vulnerability/ghsa-wf45-q9ch-q8gh WEB
    https://osv.dev/vulnerability/ghsa-xmrv-pmrh-hhx2 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-63811 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-1229 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-2303 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-24051 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-25680 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-25681 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-26958 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-27136 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-27145 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-32280 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-32281 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-32282 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-32283 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-32288 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-32289 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-32952 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-33186 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-33810 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-33811 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-33814 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-33816 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-33818 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-34986 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39817 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39819 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39820 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39821 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39822 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39823 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39824 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39825 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39826 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39827 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39828 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39829 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39830 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39831 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39832 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39833 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39834 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39835 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39836 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39883 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-41178 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-41602 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-41889 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42499 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42501 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42502 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42504 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42505 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42506 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42507 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42508 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-44503 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-46595 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-46597 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-46598 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-46600 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56852 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56853 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56854 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56855 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56858 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56859 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56860 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56862 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-73500 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-78662 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-84304 WEB

    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "vault"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "1.21.4-r0"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Multiple security vulnerabilities affect the vault package. Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. See references for individual vulnerability details.",
      "id": "CLEANSTART-2026-VO98287",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-09-10T02:48:15.538252Z",
      "references": [
        {
          "type": "ADVISORY",
          "url": "https://github.com/cleanstart-dev/cleanstart-security-advisories/tree/main/advisories/2026/CLEANSTART-2026-VO98287.json"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-63811"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-1229"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-2303"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-24051"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-25680"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-25681"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-26958"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-27136"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-27145"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-32280"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-32281"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-32282"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-32283"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-32288"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-32289"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-32952"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-33186"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-33810"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-33811"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-33814"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-33816"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-33818"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-34986"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39817"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39819"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39820"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39821"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39822"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39823"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39824"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39825"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39826"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39827"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39828"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39829"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39830"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39831"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39832"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39833"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39834"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39835"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39836"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39883"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-41178"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-41602"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-41889"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42499"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42501"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42502"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42504"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42505"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42506"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42507"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42508"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-44503"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-46595"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-46597"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-46598"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-46600"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56852"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56853"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56854"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56855"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56858"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56859"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56860"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56862"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-73500"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-78662"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-84304"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-259r-337f-4rfw"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-78h2-9frx-2jm8"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-7j59-v9qr-6fq9"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-cp6g-7hqx-qxhp"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-j88v-2chj-qfwx"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-p77j-4mvh-x3m3"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-pjcq-xvwq-hhpj"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-w67g-5rqw-f597"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-wf45-q9ch-q8gh"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-xmrv-pmrh-hhx2"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-63811"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-1229"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-2303"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-24051"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25680"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25681"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-26958"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27136"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27145"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32280"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32281"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32282"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32283"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32288"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32289"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32952"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33186"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33810"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33811"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33814"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33816"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33818"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-34986"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39817"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39819"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39820"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39821"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39822"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39823"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39824"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39825"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39826"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39827"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39828"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39829"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39830"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39831"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39832"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39833"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39834"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39835"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39836"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39883"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41178"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41602"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41889"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42499"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42501"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42502"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42504"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42505"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42506"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42507"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42508"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-44503"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46595"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46597"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46598"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46600"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56852"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56853"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56854"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56855"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56858"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56859"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56860"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56862"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-73500"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78662"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84304"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "severity": [
        {
          "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "type": "CVSS_V3"
        }
      ],
      "summary": "Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection",
      "upstream": [
        "CVE-2025-63811",
        "CVE-2026-1229",
        "CVE-2026-2303",
        "CVE-2026-24051",
        "CVE-2026-25680",
        "CVE-2026-25681",
        "CVE-2026-26958",
        "CVE-2026-27136",
        "CVE-2026-27145",
        "CVE-2026-32280",
        "CVE-2026-32281",
        "CVE-2026-32282",
        "CVE-2026-32283",
        "CVE-2026-32288",
        "CVE-2026-32289",
        "CVE-2026-32952",
        "CVE-2026-33186",
        "CVE-2026-33810",
        "CVE-2026-33811",
        "CVE-2026-33814",
        "CVE-2026-33816",
        "CVE-2026-33818",
        "CVE-2026-34986",
        "CVE-2026-39817",
        "CVE-2026-39819",
        "CVE-2026-39820",
        "CVE-2026-39821",
        "CVE-2026-39822",
        "CVE-2026-39823",
        "CVE-2026-39824",
        "CVE-2026-39825",
        "CVE-2026-39826",
        "CVE-2026-39827",
        "CVE-2026-39828",
        "CVE-2026-39829",
        "CVE-2026-39830",
        "CVE-2026-39831",
        "CVE-2026-39832",
        "CVE-2026-39833",
        "CVE-2026-39834",
        "CVE-2026-39835",
        "CVE-2026-39836",
        "CVE-2026-39883",
        "CVE-2026-41178",
        "CVE-2026-41602",
        "CVE-2026-41889",
        "CVE-2026-42499",
        "CVE-2026-42501",
        "CVE-2026-42502",
        "CVE-2026-42504",
        "CVE-2026-42505",
        "CVE-2026-42506",
        "CVE-2026-42507",
        "CVE-2026-42508",
        "CVE-2026-44503",
        "CVE-2026-46595",
        "CVE-2026-46597",
        "CVE-2026-46598",
        "CVE-2026-46600",
        "CVE-2026-56852",
        "CVE-2026-56853",
        "CVE-2026-56854",
        "CVE-2026-56855",
        "CVE-2026-56858",
        "CVE-2026-56859",
        "CVE-2026-56860",
        "CVE-2026-56862",
        "CVE-2026-73500",
        "CVE-2026-78662",
        "CVE-2026-84304",
        "ghsa-259r-337f-4rfw",
        "ghsa-78h2-9frx-2jm8",
        "ghsa-7j59-v9qr-6fq9",
        "ghsa-cp6g-7hqx-qxhp",
        "ghsa-j88v-2chj-qfwx",
        "ghsa-p77j-4mvh-x3m3",
        "ghsa-pjcq-xvwq-hhpj",
        "ghsa-w67g-5rqw-f597",
        "ghsa-wf45-q9ch-q8gh",
        "ghsa-xmrv-pmrh-hhx2"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-VU77552 (GHSA-R277-6W6Q-XMQW)

    Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    Security fixes in grafana 13.0.7-r1
    Details

    Package grafana version 13.0.7-r1 fixes 8 vulnerabilities: ghsa-r277-6w6q-xmqw, CVE-2026-73502, CVE-2026-42151, CVE-2026-44903, CVE-2026-40179...

    References

    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "grafana"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "13.0.7-r1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "13.0.7-r1"
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Package grafana version 13.0.7-r1 fixes 8 vulnerabilities: ghsa-r277-6w6q-xmqw, CVE-2026-73502, CVE-2026-42151, CVE-2026-44903, CVE-2026-40179...",
      "id": "CLEANSTART-2026-VU77552",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-09-01T11:17:16Z",
      "references": [
        {
          "type": "WEB",
          "url": "https://grafana.com"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "summary": "Security fixes in grafana 13.0.7-r1",
      "upstream": [
        "ghsa-r277-6w6q-xmqw",
        "CVE-2026-73502",
        "CVE-2026-42151",
        "CVE-2026-44903",
        "CVE-2026-40179",
        "CVE-2026-21728",
        "CVE-2026-28377",
        "ghsa-259r-337f-4rfw"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-VW52056 (GHSA-259R-337F-4RFW)

    Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    Security fixes in ollama 0.32.7-r1
    Details

    Package ollama version 0.32.7-r1 fixes 1 vulnerabilities: ghsa-259r-337f-4rfw

    References

    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "ollama"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "0.32.7-r1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "0.32.7-r1"
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Package ollama version 0.32.7-r1 fixes 1 vulnerabilities: ghsa-259r-337f-4rfw",
      "id": "CLEANSTART-2026-VW52056",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-09-01T11:17:16Z",
      "references": [
        {
          "type": "WEB",
          "url": "https://ollama.com"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "summary": "Security fixes in ollama 0.32.7-r1",
      "upstream": [
        "ghsa-259r-337f-4rfw"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-VZ50651 (CVE-2026-2303)

    Vulnerability from cleanstart – Published: 2026-08-13 12:10 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    Security fixes in mongodb 8.3.7-r0
    Details

    Package mongodb version 8.3.7-r0 fixes 2 vulnerabilities: CVE-2026-2303, ghsa-259r-337f-4rfw

    References

    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "mongodb"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "8.3.7-r0"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "8.3.7-r0"
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Package mongodb version 8.3.7-r0 fixes 2 vulnerabilities: CVE-2026-2303, ghsa-259r-337f-4rfw",
      "id": "CLEANSTART-2026-VZ50651",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-08-13T12:10:09Z",
      "references": [
        {
          "type": "WEB",
          "url": "https://www.mongodb.org"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "summary": "Security fixes in mongodb 8.3.7-r0",
      "upstream": [
        "CVE-2026-2303",
        "ghsa-259r-337f-4rfw"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-WM20973 (CVE-2026-39828)

    Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    Security fixes in ollama-fips 0.32.11-r2
    Details

    Package ollama-fips version 0.32.11-r2 fixes 33 vulnerabilities: CVE-2026-39828, CVE-2026-39829, CVE-2026-39830, CVE-2026-39831, CVE-2026-39832...

    References

    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "ollama-fips"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "0.32.11-r2"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "0.32.11-r2"
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Package ollama-fips version 0.32.11-r2 fixes 33 vulnerabilities: CVE-2026-39828, CVE-2026-39829, CVE-2026-39830, CVE-2026-39831, CVE-2026-39832...",
      "id": "CLEANSTART-2026-WM20973",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-09-01T11:17:16Z",
      "references": [
        {
          "type": "WEB",
          "url": "https://ollama.com"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "summary": "Security fixes in ollama-fips 0.32.11-r2",
      "upstream": [
        "CVE-2026-39828",
        "CVE-2026-39829",
        "CVE-2026-39830",
        "CVE-2026-39831",
        "CVE-2026-39832",
        "CVE-2026-39835",
        "CVE-2026-42508",
        "CVE-2026-46595",
        "CVE-2026-46597",
        "CVE-2026-39827",
        "CVE-2026-39833",
        "CVE-2026-39834",
        "CVE-2026-46598",
        "CVE-2026-46602",
        "CVE-2026-33809",
        "CVE-2026-33812",
        "CVE-2026-33813",
        "CVE-2026-46599",
        "CVE-2026-46601",
        "CVE-2026-46604",
        "CVE-2026-42500",
        "CVE-2026-25681",
        "CVE-2026-27136",
        "CVE-2026-33814",
        "CVE-2026-39821",
        "CVE-2026-46600",
        "CVE-2026-25680",
        "CVE-2026-42502",
        "CVE-2026-42506",
        "CVE-2026-56852",
        "CVE-2026-56864",
        "CVE-2026-56865",
        "ghsa-259r-337f-4rfw"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-WM58118 (GHSA-259R-337F-4RFW)

    Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    Security fixes in rancher-agent 2.13.7-r3
    Details

    Package rancher-agent version 2.13.7-r3 fixes 1 vulnerabilities: ghsa-259r-337f-4rfw

    References

    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "rancher-agent"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "2.13.7-r3"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "2.13.7-r3"
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Package rancher-agent version 2.13.7-r3 fixes 1 vulnerabilities: ghsa-259r-337f-4rfw",
      "id": "CLEANSTART-2026-WM58118",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-09-01T11:17:16Z",
      "references": [
        {
          "type": "WEB",
          "url": "https://github.com/rancher/rancher"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "summary": "Security fixes in rancher-agent 2.13.7-r3",
      "upstream": [
        "ghsa-259r-337f-4rfw"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-WM90638 (GHSA-259R-337F-4RFW)

    Vulnerability from cleanstart – Published: 2026-09-29 00:35 – Updated: 2026-09-28 06:30 – Source website
    VLAI
    Summary
    Security fix for ghsa-259r-337f-4rfw applied in: grafana-alloy 1.16.3-r0
    Details

    Security vulnerability affects the grafana-alloy package. This issue is resolved in later releases. See references for vulnerability details.


    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "grafana-alloy"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "1.16.3-r0"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Security vulnerability affects the grafana-alloy package. This issue is resolved in later releases. See references for vulnerability details.",
      "id": "CLEANSTART-2026-WM90638",
      "modified": "2026-09-28T06:30:11Z",
      "published": "2026-09-29T00:35:03.276396Z",
      "references": [
        {
          "type": "ADVISORY",
          "url": "https://github.com/cleanstart-dev/cleanstart-security-advisories/tree/main/advisories/2026/CLEANSTART-2026-WM90638.json"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-259r-337f-4rfw"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "summary": "Security fix for ghsa-259r-337f-4rfw applied in: grafana-alloy 1.16.3-r0",
      "upstream": [
        "ghsa-259r-337f-4rfw"
      ]
    }

    CLEANSTART-2026-WX98343 (GHSA-JPCW-4WR7-C3VQ)

    Vulnerability from cleanstart – Published: 2026-08-13 12:10 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    Security fixes in grafana 12.4.6-r0
    Details

    Package grafana version 12.4.6-r0 fixes 4 vulnerabilities: ghsa-jpcw-4wr7-c3vq, ghsa-r277-6w6q-xmqw, ghsa-gcjh-h69q-9w9g, ghsa-259r-337f-4rfw

    References

    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "grafana"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "12.4.6-r0"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "12.4.6-r0"
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Package grafana version 12.4.6-r0 fixes 4 vulnerabilities: ghsa-jpcw-4wr7-c3vq, ghsa-r277-6w6q-xmqw, ghsa-gcjh-h69q-9w9g, ghsa-259r-337f-4rfw",
      "id": "CLEANSTART-2026-WX98343",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-08-13T12:10:09Z",
      "references": [
        {
          "type": "WEB",
          "url": "https://grafana.com"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "summary": "Security fixes in grafana 12.4.6-r0",
      "upstream": [
        "ghsa-jpcw-4wr7-c3vq",
        "ghsa-r277-6w6q-xmqw",
        "ghsa-gcjh-h69q-9w9g",
        "ghsa-259r-337f-4rfw"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-WY48690 (GHSA-259R-337F-4RFW)

    Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    Security fixes in argo-cd 3.4.7-r2
    Details

    Package argo-cd version 3.4.7-r2 fixes 1 vulnerabilities: ghsa-259r-337f-4rfw

    References

    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "argo-cd"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "3.4.7-r2"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "3.4.7-r2"
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Package argo-cd version 3.4.7-r2 fixes 1 vulnerabilities: ghsa-259r-337f-4rfw",
      "id": "CLEANSTART-2026-WY48690",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-09-01T11:17:16Z",
      "references": [
        {
          "type": "WEB",
          "url": "https://github.com/argoproj/argo-cd"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "summary": "Security fixes in argo-cd 3.4.7-r2",
      "upstream": [
        "ghsa-259r-337f-4rfw"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-XC36921 (CVE-2026-56852)

    Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    Security fixes in kubernetes-event-exporter 1.5-r3
    Details

    Package kubernetes-event-exporter version 1.5-r3 fixes 3 vulnerabilities: CVE-2026-56852, CVE-2026-41178, ghsa-259r-337f-4rfw


    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "kubernetes-event-exporter"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "1.5-r3"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "1.5-r3"
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Package kubernetes-event-exporter version 1.5-r3 fixes 3 vulnerabilities: CVE-2026-56852, CVE-2026-41178, ghsa-259r-337f-4rfw",
      "id": "CLEANSTART-2026-XC36921",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-09-01T11:17:16Z",
      "references": [
        {
          "type": "WEB",
          "url": "https://github.com/resmoio/kubernetes-event-exporter"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "summary": "Security fixes in kubernetes-event-exporter 1.5-r3",
      "upstream": [
        "CVE-2026-56852",
        "CVE-2026-41178",
        "ghsa-259r-337f-4rfw"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-XD35510 (CVE-2023-42821)

    Vulnerability from cleanstart – Published: 2026-09-15 01:09 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    gRPC-Go is the Go language implementation of gRPC
    Details

    Multiple security vulnerabilities affect the kube-metrics-adapter package. gRPC-Go is the Go language implementation of gRPC. See references for individual vulnerability details.

    References
    https://github.com/cleanstart-dev/cleanstart-secu… ADVISORY
    https://osv.dev/vulnerability/CVE-2023-42821 WEB
    https://osv.dev/vulnerability/CVE-2026-33818 WEB
    https://osv.dev/vulnerability/CVE-2026-39821 WEB
    https://osv.dev/vulnerability/CVE-2026-40890 WEB
    https://osv.dev/vulnerability/CVE-2026-40898 WEB
    https://osv.dev/vulnerability/CVE-2026-41178 WEB
    https://osv.dev/vulnerability/CVE-2026-46600 WEB
    https://osv.dev/vulnerability/CVE-2026-55677 WEB
    https://osv.dev/vulnerability/CVE-2026-56853 WEB
    https://osv.dev/vulnerability/CVE-2026-56858 WEB
    https://osv.dev/vulnerability/CVE-2026-56859 WEB
    https://osv.dev/vulnerability/CVE-2026-56860 WEB
    https://osv.dev/vulnerability/CVE-2026-56862 WEB
    https://osv.dev/vulnerability/CVE-2026-73500 WEB
    https://osv.dev/vulnerability/CVE-2026-84303 WEB
    https://osv.dev/vulnerability/CVE-2026-84304 WEB
    https://osv.dev/vulnerability/CVE-2026-84445 WEB
    https://osv.dev/vulnerability/ghsa-259r-337f-4rfw WEB
    https://osv.dev/vulnerability/ghsa-gcjh-h69q-9w9g WEB
    https://osv.dev/vulnerability/ghsa-hrxh-6v49-42gf WEB
    https://nvd.nist.gov/vuln/detail/CVE-2023-42821 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-33818 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39821 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-40890 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-40898 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-41178 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-46600 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-55677 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56853 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56858 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56859 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56860 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56862 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-73500 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-84303 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-84304 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-84445 WEB

    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "kube-metrics-adapter"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "0.2.9-r4"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Multiple security vulnerabilities affect the kube-metrics-adapter package. gRPC-Go is the Go language implementation of gRPC. See references for individual vulnerability details.",
      "id": "CLEANSTART-2026-XD35510",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-09-15T01:09:12.286403Z",
      "references": [
        {
          "type": "ADVISORY",
          "url": "https://github.com/cleanstart-dev/cleanstart-security-advisories/tree/main/advisories/2026/CLEANSTART-2026-XD35510.json"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2023-42821"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-33818"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39821"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-40890"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-40898"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-41178"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-46600"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-55677"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56853"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56858"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56859"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56860"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56862"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-73500"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-84303"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-84304"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-84445"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-259r-337f-4rfw"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-gcjh-h69q-9w9g"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-hrxh-6v49-42gf"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-42821"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33818"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39821"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-40890"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-40898"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41178"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46600"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-55677"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56853"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56858"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56859"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56860"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56862"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-73500"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84303"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84304"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84445"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "severity": [
        {
          "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "type": "CVSS_V3"
        }
      ],
      "summary": "gRPC-Go is the Go language implementation of gRPC",
      "upstream": [
        "CVE-2023-42821",
        "CVE-2026-33818",
        "CVE-2026-39821",
        "CVE-2026-40890",
        "CVE-2026-40898",
        "CVE-2026-41178",
        "CVE-2026-46600",
        "CVE-2026-55677",
        "CVE-2026-56853",
        "CVE-2026-56858",
        "CVE-2026-56859",
        "CVE-2026-56860",
        "CVE-2026-56862",
        "CVE-2026-73500",
        "CVE-2026-84303",
        "CVE-2026-84304",
        "CVE-2026-84445",
        "ghsa-259r-337f-4rfw",
        "ghsa-gcjh-h69q-9w9g",
        "ghsa-hrxh-6v49-42gf"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-XK29798 (CVE-2026-56864)

    Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    Security fixes in ollama 0.32.11-r1
    Details

    Package ollama version 0.32.11-r1 fixes 3 vulnerabilities: CVE-2026-56864, CVE-2026-56865, ghsa-259r-337f-4rfw

    References

    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "ollama"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "0.32.11-r1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "0.32.11-r1"
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Package ollama version 0.32.11-r1 fixes 3 vulnerabilities: CVE-2026-56864, CVE-2026-56865, ghsa-259r-337f-4rfw",
      "id": "CLEANSTART-2026-XK29798",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-09-01T11:17:16Z",
      "references": [
        {
          "type": "WEB",
          "url": "https://ollama.com"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "summary": "Security fixes in ollama 0.32.11-r1",
      "upstream": [
        "CVE-2026-56864",
        "CVE-2026-56865",
        "ghsa-259r-337f-4rfw"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-XT48985 (CVE-2026-50195)

    Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    Security fixes in rancher-agent 2.12.11-r1
    Details

    Package rancher-agent version 2.12.11-r1 fixes 18 vulnerabilities: CVE-2026-50195, CVE-2026-53492, CVE-2026-53489, CVE-2026-46680, CVE-2026-53488...

    References

    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "rancher-agent"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "2.12.11-r1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "2.12.11-r1"
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Package rancher-agent version 2.12.11-r1 fixes 18 vulnerabilities: CVE-2026-50195, CVE-2026-53492, CVE-2026-53489, CVE-2026-46680, CVE-2026-53488...",
      "id": "CLEANSTART-2026-XT48985",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-09-01T11:17:16Z",
      "references": [
        {
          "type": "WEB",
          "url": "https://github.com/rancher/rancher"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "summary": "Security fixes in rancher-agent 2.12.11-r1",
      "upstream": [
        "CVE-2026-50195",
        "CVE-2026-53492",
        "CVE-2026-53489",
        "CVE-2026-46680",
        "CVE-2026-53488",
        "CVE-2026-47262",
        "ghsa-hrxh-6v49-42gf",
        "CVE-2026-56864",
        "CVE-2026-56865",
        "CVE-2026-56852",
        "CVE-2026-50163",
        "CVE-2026-48978",
        "CVE-2026-50151",
        "CVE-2026-50162",
        "ghsa-vh4v-2xq2-g5cg",
        "ghsa-gcjh-h69q-9w9g",
        "CVE-2026-41178",
        "ghsa-259r-337f-4rfw"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-XV71690 (CVE-2026-53492)

    Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    Security fixes in rancher-fleet-agent 0.14.8-r1
    Details

    Package rancher-fleet-agent version 0.14.8-r1 fixes 39 vulnerabilities: CVE-2026-53492, CVE-2026-50195, CVE-2026-53489, CVE-2026-46680, CVE-2026-53488...

    References

    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "rancher-fleet-agent"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "0.14.8-r1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "0.14.8-r1"
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Package rancher-fleet-agent version 0.14.8-r1 fixes 39 vulnerabilities: CVE-2026-53492, CVE-2026-50195, CVE-2026-53489, CVE-2026-46680, CVE-2026-53488...",
      "id": "CLEANSTART-2026-XV71690",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-09-01T11:17:16Z",
      "references": [
        {
          "type": "WEB",
          "url": "https://github.com/rancher/fleet"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "summary": "Security fixes in rancher-fleet-agent 0.14.8-r1",
      "upstream": [
        "CVE-2026-53492",
        "CVE-2026-50195",
        "CVE-2026-53489",
        "CVE-2026-46680",
        "CVE-2026-53488",
        "CVE-2026-47262",
        "CVE-2026-42508",
        "CVE-2026-39835",
        "CVE-2026-46598",
        "CVE-2026-39828",
        "CVE-2026-39829",
        "CVE-2026-46597",
        "CVE-2026-39830",
        "CVE-2026-39831",
        "CVE-2026-39832",
        "CVE-2026-39833",
        "CVE-2026-39834",
        "CVE-2026-46595",
        "CVE-2026-39827",
        "CVE-2026-33186",
        "ghsa-hrxh-6v49-42gf",
        "CVE-2026-46600",
        "CVE-2026-25681",
        "CVE-2026-27136",
        "CVE-2026-39821",
        "CVE-2026-42502",
        "CVE-2026-42506",
        "CVE-2026-25680",
        "CVE-2026-29181",
        "CVE-2026-35469",
        "CVE-2026-56852",
        "CVE-2026-50163",
        "CVE-2026-48978",
        "CVE-2026-50151",
        "CVE-2026-50162",
        "ghsa-vh4v-2xq2-g5cg",
        "CVE-2026-39824",
        "CVE-2026-35206",
        "ghsa-259r-337f-4rfw"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-XV99350 (CVE-2025-47912)

    Vulnerability from cleanstart – Published: 2026-09-10 01:29 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    malicious GOSUMDB was capable of serving arbitrary module content not contained within the transparency log
    Details

    Multiple security vulnerabilities affect the kyverno package. A malicious GOSUMDB was capable of serving arbitrary module content not contained within the transparency log. See references for individual vulnerability details.

    References
    https://github.com/cleanstart-dev/cleanstart-secu… ADVISORY
    https://osv.dev/vulnerability/CVE-2025-47912 WEB
    https://osv.dev/vulnerability/CVE-2025-58183 WEB
    https://osv.dev/vulnerability/CVE-2025-58185 WEB
    https://osv.dev/vulnerability/CVE-2025-58186 WEB
    https://osv.dev/vulnerability/CVE-2025-58187 WEB
    https://osv.dev/vulnerability/CVE-2025-58188 WEB
    https://osv.dev/vulnerability/CVE-2025-58189 WEB
    https://osv.dev/vulnerability/CVE-2025-61723 WEB
    https://osv.dev/vulnerability/CVE-2025-61724 WEB
    https://osv.dev/vulnerability/CVE-2025-61725 WEB
    https://osv.dev/vulnerability/CVE-2025-61729 WEB
    https://osv.dev/vulnerability/CVE-2026-24122 WEB
    https://osv.dev/vulnerability/CVE-2026-32952 WEB
    https://osv.dev/vulnerability/CVE-2026-39395 WEB
    https://osv.dev/vulnerability/CVE-2026-39984 WEB
    https://osv.dev/vulnerability/CVE-2026-48978 WEB
    https://osv.dev/vulnerability/CVE-2026-49478 WEB
    https://osv.dev/vulnerability/CVE-2026-49834 WEB
    https://osv.dev/vulnerability/CVE-2026-50151 WEB
    https://osv.dev/vulnerability/CVE-2026-50162 WEB
    https://osv.dev/vulnerability/CVE-2026-50163 WEB
    https://osv.dev/vulnerability/CVE-2026-54787 WEB
    https://osv.dev/vulnerability/CVE-2026-56864 WEB
    https://osv.dev/vulnerability/CVE-2026-56865 WEB
    https://osv.dev/vulnerability/ghsa-259r-337f-4rfw WEB
    https://osv.dev/vulnerability/ghsa-gcjh-h69q-9w9g WEB
    https://osv.dev/vulnerability/ghsa-hrxh-6v49-42gf WEB
    https://osv.dev/vulnerability/ghsa-pmwq-pjrm-6p5r WEB
    https://osv.dev/vulnerability/ghsa-vh4v-2xq2-g5cg WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-47912 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-58183 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-58185 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-58186 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-58187 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-58188 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-58189 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-61723 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-61724 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-61725 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-61729 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-24122 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-32952 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39395 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39984 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-48978 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-49478 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-49834 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-50151 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-50162 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-50163 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-54787 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56864 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56865 WEB

    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "kyverno"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "1.17.2-r3"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Multiple security vulnerabilities affect the kyverno package. A malicious GOSUMDB was capable of serving arbitrary module content not contained within the transparency log. See references for individual vulnerability details.",
      "id": "CLEANSTART-2026-XV99350",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-09-10T01:29:08.629807Z",
      "references": [
        {
          "type": "ADVISORY",
          "url": "https://github.com/cleanstart-dev/cleanstart-security-advisories/tree/main/advisories/2026/CLEANSTART-2026-XV99350.json"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-47912"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-58183"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-58185"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-58186"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-58187"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-58188"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-58189"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-61723"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-61724"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-61725"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-61729"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-24122"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-32952"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39395"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39984"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-48978"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-49478"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-49834"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-50151"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-50162"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-50163"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-54787"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56864"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56865"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-259r-337f-4rfw"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-gcjh-h69q-9w9g"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-hrxh-6v49-42gf"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-pmwq-pjrm-6p5r"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-vh4v-2xq2-g5cg"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47912"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58183"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58185"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58186"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58187"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58188"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58189"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61723"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61724"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61725"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61729"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-24122"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32952"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39395"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39984"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-48978"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-49478"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-49834"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-50151"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-50162"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-50163"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54787"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56864"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56865"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "severity": [
        {
          "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "type": "CVSS_V3"
        }
      ],
      "summary": "malicious GOSUMDB was capable of serving arbitrary module content not contained within the transparency log",
      "upstream": [
        "CVE-2025-47912",
        "CVE-2025-58183",
        "CVE-2025-58185",
        "CVE-2025-58186",
        "CVE-2025-58187",
        "CVE-2025-58188",
        "CVE-2025-58189",
        "CVE-2025-61723",
        "CVE-2025-61724",
        "CVE-2025-61725",
        "CVE-2025-61729",
        "CVE-2026-24122",
        "CVE-2026-32952",
        "CVE-2026-39395",
        "CVE-2026-39984",
        "CVE-2026-48978",
        "CVE-2026-49478",
        "CVE-2026-49834",
        "CVE-2026-50151",
        "CVE-2026-50162",
        "CVE-2026-50163",
        "CVE-2026-54787",
        "CVE-2026-56864",
        "CVE-2026-56865",
        "ghsa-259r-337f-4rfw",
        "ghsa-gcjh-h69q-9w9g",
        "ghsa-hrxh-6v49-42gf",
        "ghsa-pmwq-pjrm-6p5r",
        "ghsa-vh4v-2xq2-g5cg"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-YC27448 (CVE-2026-56860)

    Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    Security fixes in prometheus-redis-exporter-fips 1.87.0-r1
    Details

    Package prometheus-redis-exporter-fips version 1.87.0-r1 fixes 8 vulnerabilities: CVE-2026-56860, CVE-2026-56858, CVE-2026-33818, CVE-2026-56853, CVE-2026-56859...


    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "prometheus-redis-exporter-fips"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "1.87.0-r1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "1.87.0-r1"
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Package prometheus-redis-exporter-fips version 1.87.0-r1 fixes 8 vulnerabilities: CVE-2026-56860, CVE-2026-56858, CVE-2026-33818, CVE-2026-56853, CVE-2026-56859...",
      "id": "CLEANSTART-2026-YC27448",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-09-01T11:17:16Z",
      "references": [
        {
          "type": "WEB",
          "url": "https://github.com/oliver006/redis_exporter"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "summary": "Security fixes in prometheus-redis-exporter-fips 1.87.0-r1",
      "upstream": [
        "CVE-2026-56860",
        "CVE-2026-56858",
        "CVE-2026-33818",
        "CVE-2026-56853",
        "CVE-2026-56859",
        "CVE-2026-56862",
        "CVE-2026-39821",
        "ghsa-259r-337f-4rfw"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-YI59826 (GHSA-HRXH-6V49-42GF)

    Vulnerability from cleanstart – Published: 2026-08-13 12:10 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    Security fixes in gitea 1.26.4-r1
    Details

    Package gitea version 1.26.4-r1 fixes 9 vulnerabilities: ghsa-hrxh-6v49-42gf, CVE-2026-56852, CVE-2026-71556, CVE-2026-71557, ghsa-259r-337f-4rfw...

    References

    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "gitea"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "1.26.4-r1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "1.26.4-r1"
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Package gitea version 1.26.4-r1 fixes 9 vulnerabilities: ghsa-hrxh-6v49-42gf, CVE-2026-56852, CVE-2026-71556, CVE-2026-71557, ghsa-259r-337f-4rfw...",
      "id": "CLEANSTART-2026-YI59826",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-08-13T12:10:09Z",
      "references": [
        {
          "type": "WEB",
          "url": "https://github.com/go-gitea/gitea"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "summary": "Security fixes in gitea 1.26.4-r1",
      "upstream": [
        "ghsa-hrxh-6v49-42gf",
        "CVE-2026-56852",
        "CVE-2026-71556",
        "CVE-2026-71557",
        "ghsa-259r-337f-4rfw",
        "CVE-2026-46600",
        "ghsa-3fxj-6jh8-hvhx",
        "ghsa-9g5q-2w5x-hmxf",
        "ghsa-rjr7-jggh-pgcp"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-YL93188 (CVE-2026-46602)

    Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    Security fixes in ollama 0.32.11-r3
    Details

    Package ollama version 0.32.11-r3 fixes 11 vulnerabilities: CVE-2026-46602, CVE-2026-33809, CVE-2026-33812, CVE-2026-33813, CVE-2026-46599...

    References

    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "ollama"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "0.32.11-r3"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "0.32.11-r3"
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Package ollama version 0.32.11-r3 fixes 11 vulnerabilities: CVE-2026-46602, CVE-2026-33809, CVE-2026-33812, CVE-2026-33813, CVE-2026-46599...",
      "id": "CLEANSTART-2026-YL93188",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-09-01T11:17:16Z",
      "references": [
        {
          "type": "WEB",
          "url": "https://ollama.com"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "summary": "Security fixes in ollama 0.32.11-r3",
      "upstream": [
        "CVE-2026-46602",
        "CVE-2026-33809",
        "CVE-2026-33812",
        "CVE-2026-33813",
        "CVE-2026-46599",
        "CVE-2026-46601",
        "CVE-2026-46604",
        "CVE-2026-42500",
        "CVE-2026-56864",
        "CVE-2026-56865",
        "ghsa-259r-337f-4rfw"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-YO86996 (CVE-2026-25680)

    Vulnerability from cleanstart – Published: 2026-09-11 00:49 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection
    Details

    Multiple security vulnerabilities affect the cadvisor package. Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. See references for individual vulnerability details.

    References
    https://github.com/cleanstart-dev/cleanstart-secu… ADVISORY
    https://osv.dev/vulnerability/CVE-2026-25680 WEB
    https://osv.dev/vulnerability/CVE-2026-25681 WEB
    https://osv.dev/vulnerability/CVE-2026-27136 WEB
    https://osv.dev/vulnerability/CVE-2026-27145 WEB
    https://osv.dev/vulnerability/CVE-2026-29181 WEB
    https://osv.dev/vulnerability/CVE-2026-33186 WEB
    https://osv.dev/vulnerability/CVE-2026-33818 WEB
    https://osv.dev/vulnerability/CVE-2026-39821 WEB
    https://osv.dev/vulnerability/CVE-2026-39822 WEB
    https://osv.dev/vulnerability/CVE-2026-39824 WEB
    https://osv.dev/vulnerability/CVE-2026-39827 WEB
    https://osv.dev/vulnerability/CVE-2026-39828 WEB
    https://osv.dev/vulnerability/CVE-2026-39829 WEB
    https://osv.dev/vulnerability/CVE-2026-39830 WEB
    https://osv.dev/vulnerability/CVE-2026-39831 WEB
    https://osv.dev/vulnerability/CVE-2026-39832 WEB
    https://osv.dev/vulnerability/CVE-2026-39833 WEB
    https://osv.dev/vulnerability/CVE-2026-39834 WEB
    https://osv.dev/vulnerability/CVE-2026-39835 WEB
    https://osv.dev/vulnerability/CVE-2026-41579 WEB
    https://osv.dev/vulnerability/CVE-2026-42502 WEB
    https://osv.dev/vulnerability/CVE-2026-42504 WEB
    https://osv.dev/vulnerability/CVE-2026-42505 WEB
    https://osv.dev/vulnerability/CVE-2026-42506 WEB
    https://osv.dev/vulnerability/CVE-2026-42507 WEB
    https://osv.dev/vulnerability/CVE-2026-42508 WEB
    https://osv.dev/vulnerability/CVE-2026-46595 WEB
    https://osv.dev/vulnerability/CVE-2026-46597 WEB
    https://osv.dev/vulnerability/CVE-2026-46598 WEB
    https://osv.dev/vulnerability/CVE-2026-46600 WEB
    https://osv.dev/vulnerability/CVE-2026-56852 WEB
    https://osv.dev/vulnerability/CVE-2026-56853 WEB
    https://osv.dev/vulnerability/CVE-2026-56855 WEB
    https://osv.dev/vulnerability/CVE-2026-56858 WEB
    https://osv.dev/vulnerability/CVE-2026-56859 WEB
    https://osv.dev/vulnerability/CVE-2026-56860 WEB
    https://osv.dev/vulnerability/CVE-2026-56862 WEB
    https://osv.dev/vulnerability/CVE-2026-78662 WEB
    https://osv.dev/vulnerability/CVE-2026-84303 WEB
    https://osv.dev/vulnerability/CVE-2026-84304 WEB
    https://osv.dev/vulnerability/CVE-2026-84445 WEB
    https://osv.dev/vulnerability/ghsa-259r-337f-4rfw WEB
    https://osv.dev/vulnerability/ghsa-hrxh-6v49-42gf WEB
    https://osv.dev/vulnerability/ghsa-mh2q-q3fh-2475 WEB
    https://osv.dev/vulnerability/ghsa-xjvp-4fhw-gc47 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-25680 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-25681 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-27136 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-27145 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-29181 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-33186 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-33818 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39821 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39822 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39824 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39827 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39828 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39829 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39830 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39831 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39832 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39833 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39834 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39835 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-41579 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42502 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42504 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42505 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42506 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42507 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42508 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-46595 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-46597 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-46598 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-46600 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56852 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56853 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56855 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56858 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56859 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56860 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56862 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-78662 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-84303 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-84304 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-84445 WEB

    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "cadvisor"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "0.57.0-r6"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Multiple security vulnerabilities affect the cadvisor package. Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. See references for individual vulnerability details.",
      "id": "CLEANSTART-2026-YO86996",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-09-11T00:49:41.696255Z",
      "references": [
        {
          "type": "ADVISORY",
          "url": "https://github.com/cleanstart-dev/cleanstart-security-advisories/tree/main/advisories/2026/CLEANSTART-2026-YO86996.json"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-25680"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-25681"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-27136"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-27145"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-29181"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-33186"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-33818"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39821"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39822"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39824"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39827"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39828"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39829"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39830"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39831"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39832"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39833"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39834"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39835"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-41579"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42502"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42504"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42505"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42506"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42507"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42508"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-46595"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-46597"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-46598"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-46600"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56852"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56853"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56855"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56858"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56859"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56860"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56862"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-78662"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-84303"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-84304"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-84445"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-259r-337f-4rfw"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-hrxh-6v49-42gf"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-mh2q-q3fh-2475"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-xjvp-4fhw-gc47"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25680"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25681"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27136"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27145"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-29181"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33186"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33818"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39821"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39822"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39824"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39827"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39828"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39829"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39830"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39831"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39832"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39833"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39834"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39835"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41579"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42502"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42504"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42505"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42506"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42507"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42508"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46595"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46597"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46598"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46600"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56852"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56853"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56855"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56858"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56859"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56860"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56862"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78662"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84303"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84304"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84445"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "severity": [
        {
          "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "type": "CVSS_V3"
        }
      ],
      "summary": "Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection",
      "upstream": [
        "CVE-2026-25680",
        "CVE-2026-25681",
        "CVE-2026-27136",
        "CVE-2026-27145",
        "CVE-2026-29181",
        "CVE-2026-33186",
        "CVE-2026-33818",
        "CVE-2026-39821",
        "CVE-2026-39822",
        "CVE-2026-39824",
        "CVE-2026-39827",
        "CVE-2026-39828",
        "CVE-2026-39829",
        "CVE-2026-39830",
        "CVE-2026-39831",
        "CVE-2026-39832",
        "CVE-2026-39833",
        "CVE-2026-39834",
        "CVE-2026-39835",
        "CVE-2026-41579",
        "CVE-2026-42502",
        "CVE-2026-42504",
        "CVE-2026-42505",
        "CVE-2026-42506",
        "CVE-2026-42507",
        "CVE-2026-42508",
        "CVE-2026-46595",
        "CVE-2026-46597",
        "CVE-2026-46598",
        "CVE-2026-46600",
        "CVE-2026-56852",
        "CVE-2026-56853",
        "CVE-2026-56855",
        "CVE-2026-56858",
        "CVE-2026-56859",
        "CVE-2026-56860",
        "CVE-2026-56862",
        "CVE-2026-78662",
        "CVE-2026-84303",
        "CVE-2026-84304",
        "CVE-2026-84445",
        "ghsa-259r-337f-4rfw",
        "ghsa-hrxh-6v49-42gf",
        "ghsa-mh2q-q3fh-2475",
        "ghsa-xjvp-4fhw-gc47"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-YQ04725 (CVE-2026-42508)

    Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    Security fixes in prometheus-pushgateway 1.10.0-r3
    Details

    Package prometheus-pushgateway version 1.10.0-r3 fixes 35 vulnerabilities: CVE-2026-42508, CVE-2025-47914, CVE-2025-58181, CVE-2026-39835, CVE-2026-46598...


    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "prometheus-pushgateway"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "1.10.0-r3"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "1.10.0-r3"
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Package prometheus-pushgateway version 1.10.0-r3 fixes 35 vulnerabilities: CVE-2026-42508, CVE-2025-47914, CVE-2025-58181, CVE-2026-39835, CVE-2026-46598...",
      "id": "CLEANSTART-2026-YQ04725",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-09-01T11:17:16Z",
      "references": [
        {
          "type": "WEB",
          "url": "https://github.com/prometheus/pushgateway"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "summary": "Security fixes in prometheus-pushgateway 1.10.0-r3",
      "upstream": [
        "CVE-2026-42508",
        "CVE-2025-47914",
        "CVE-2025-58181",
        "CVE-2026-39835",
        "CVE-2026-46598",
        "CVE-2026-39828",
        "CVE-2025-22869",
        "CVE-2025-47913",
        "CVE-2026-39829",
        "CVE-2026-46597",
        "CVE-2024-45337",
        "CVE-2026-39830",
        "CVE-2026-39831",
        "CVE-2026-39832",
        "CVE-2026-39833",
        "CVE-2026-39834",
        "CVE-2026-46595",
        "CVE-2026-39827",
        "CVE-2026-46600",
        "CVE-2025-22870",
        "CVE-2024-45338",
        "CVE-2026-25681",
        "CVE-2026-27136",
        "CVE-2026-33814",
        "CVE-2026-39821",
        "CVE-2025-22872",
        "CVE-2025-47911",
        "CVE-2025-58190",
        "CVE-2026-42502",
        "CVE-2026-42506",
        "CVE-2026-25680",
        "CVE-2026-42151",
        "CVE-2026-44903",
        "CVE-2026-42154",
        "ghsa-259r-337f-4rfw"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-YQ30478 (CVE-2025-15558)

    Vulnerability from cleanstart – Published: 2026-09-18 01:18 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for CVE-2...
    Details

    Multiple security vulnerabilities affect the dynatrace-operator package. The source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for CVE-2026-46595. See references for individual vulnerability details.

    References
    https://github.com/cleanstart-dev/cleanstart-secu… ADVISORY
    https://osv.dev/vulnerability/CVE-2025-15558 WEB
    https://osv.dev/vulnerability/CVE-2026-33818 WEB
    https://osv.dev/vulnerability/CVE-2026-39821 WEB
    https://osv.dev/vulnerability/CVE-2026-39822 WEB
    https://osv.dev/vulnerability/CVE-2026-41178 WEB
    https://osv.dev/vulnerability/CVE-2026-42504 WEB
    https://osv.dev/vulnerability/CVE-2026-42505 WEB
    https://osv.dev/vulnerability/CVE-2026-46600 WEB
    https://osv.dev/vulnerability/CVE-2026-56852 WEB
    https://osv.dev/vulnerability/CVE-2026-56853 WEB
    https://osv.dev/vulnerability/CVE-2026-56854 WEB
    https://osv.dev/vulnerability/CVE-2026-56855 WEB
    https://osv.dev/vulnerability/CVE-2026-56858 WEB
    https://osv.dev/vulnerability/CVE-2026-56859 WEB
    https://osv.dev/vulnerability/CVE-2026-56860 WEB
    https://osv.dev/vulnerability/CVE-2026-56862 WEB
    https://osv.dev/vulnerability/CVE-2026-56864 WEB
    https://osv.dev/vulnerability/CVE-2026-56865 WEB
    https://osv.dev/vulnerability/CVE-2026-78662 WEB
    https://osv.dev/vulnerability/CVE-2026-84303 WEB
    https://osv.dev/vulnerability/CVE-2026-84304 WEB
    https://osv.dev/vulnerability/CVE-2026-84445 WEB
    https://osv.dev/vulnerability/ghsa-259r-337f-4rfw WEB
    https://osv.dev/vulnerability/ghsa-hrxh-6v49-42gf WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-15558 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-33818 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39821 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39822 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-41178 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42504 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42505 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-46600 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56852 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56853 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56854 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56855 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56858 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56859 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56860 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56862 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56864 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56865 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-78662 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-84303 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-84304 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-84445 WEB

    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "dynatrace-operator"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "1.8.1-r8"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Multiple security vulnerabilities affect the dynatrace-operator package. The source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for CVE-2026-46595. See references for individual vulnerability details.",
      "id": "CLEANSTART-2026-YQ30478",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-09-18T01:18:28.963406Z",
      "references": [
        {
          "type": "ADVISORY",
          "url": "https://github.com/cleanstart-dev/cleanstart-security-advisories/tree/main/advisories/2026/CLEANSTART-2026-YQ30478.json"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-15558"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-33818"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39821"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39822"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-41178"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42504"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42505"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-46600"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56852"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56853"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56854"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56855"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56858"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56859"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56860"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56862"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56864"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56865"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-78662"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-84303"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-84304"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-84445"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-259r-337f-4rfw"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-hrxh-6v49-42gf"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-15558"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33818"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39821"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39822"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41178"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42504"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42505"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46600"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56852"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56853"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56854"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56855"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56858"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56859"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56860"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56862"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56864"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56865"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78662"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84303"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84304"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84445"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "severity": [
        {
          "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "type": "CVSS_V3"
        }
      ],
      "summary": "source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for CVE-2...",
      "upstream": [
        "CVE-2025-15558",
        "CVE-2026-33818",
        "CVE-2026-39821",
        "CVE-2026-39822",
        "CVE-2026-41178",
        "CVE-2026-42504",
        "CVE-2026-42505",
        "CVE-2026-46600",
        "CVE-2026-56852",
        "CVE-2026-56853",
        "CVE-2026-56854",
        "CVE-2026-56855",
        "CVE-2026-56858",
        "CVE-2026-56859",
        "CVE-2026-56860",
        "CVE-2026-56862",
        "CVE-2026-56864",
        "CVE-2026-56865",
        "CVE-2026-78662",
        "CVE-2026-84303",
        "CVE-2026-84304",
        "CVE-2026-84445",
        "ghsa-259r-337f-4rfw",
        "ghsa-hrxh-6v49-42gf"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-YR40466 (CVE-2026-53713)

    Vulnerability from cleanstart – Published: 2026-08-13 12:10 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    Security fixes in tigera-operator 1.39.3-r1
    Details

    Package tigera-operator version 1.39.3-r1 fixes 17 vulnerabilities: CVE-2026-53713, CVE-2026-53714, CVE-2026-53715, CVE-2026-53716, CVE-2026-53717...

    References

    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "tigera-operator"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "1.39.3-r1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "1.39.3-r1"
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Package tigera-operator version 1.39.3-r1 fixes 17 vulnerabilities: CVE-2026-53713, CVE-2026-53714, CVE-2026-53715, CVE-2026-53716, CVE-2026-53717...",
      "id": "CLEANSTART-2026-YR40466",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-08-13T12:10:09Z",
      "references": [
        {
          "type": "WEB",
          "url": "https://github.com/tigera/operator"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "summary": "Security fixes in tigera-operator 1.39.3-r1",
      "upstream": [
        "CVE-2026-53713",
        "CVE-2026-53714",
        "CVE-2026-53715",
        "CVE-2026-53716",
        "CVE-2026-53717",
        "CVE-2026-53718",
        "CVE-2026-53719",
        "CVE-2026-22771",
        "ghsa-wcrf-9vrr-854f",
        "ghsa-22xc-xg2r-9j7v",
        "ghsa-8fv2-88gg-hm7q",
        "ghsa-cxpq-8v7q-cg56",
        "ghsa-fcrp-7gc2-93g7",
        "ghsa-h7pq-86h8-rp5x",
        "ghsa-m2v6-2jmh-4c68",
        "ghsa-xrwg-mqj6-6m22",
        "ghsa-259r-337f-4rfw"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-YS01797 (CVE-2026-27145)

    Vulnerability from cleanstart – Published: 2026-09-10 02:14 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label
    Details

    Multiple security vulnerabilities affect the calico package. The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. See references for individual vulnerability details.

    References
    https://github.com/cleanstart-dev/cleanstart-secu… ADVISORY
    https://osv.dev/vulnerability/CVE-2026-27145 WEB
    https://osv.dev/vulnerability/CVE-2026-29181 WEB
    https://osv.dev/vulnerability/CVE-2026-32280 WEB
    https://osv.dev/vulnerability/CVE-2026-32281 WEB
    https://osv.dev/vulnerability/CVE-2026-32282 WEB
    https://osv.dev/vulnerability/CVE-2026-32283 WEB
    https://osv.dev/vulnerability/CVE-2026-32288 WEB
    https://osv.dev/vulnerability/CVE-2026-32289 WEB
    https://osv.dev/vulnerability/CVE-2026-33186 WEB
    https://osv.dev/vulnerability/CVE-2026-33810 WEB
    https://osv.dev/vulnerability/CVE-2026-33811 WEB
    https://osv.dev/vulnerability/CVE-2026-33814 WEB
    https://osv.dev/vulnerability/CVE-2026-33818 WEB
    https://osv.dev/vulnerability/CVE-2026-39820 WEB
    https://osv.dev/vulnerability/CVE-2026-39821 WEB
    https://osv.dev/vulnerability/CVE-2026-39823 WEB
    https://osv.dev/vulnerability/CVE-2026-39825 WEB
    https://osv.dev/vulnerability/CVE-2026-39826 WEB
    https://osv.dev/vulnerability/CVE-2026-39827 WEB
    https://osv.dev/vulnerability/CVE-2026-39828 WEB
    https://osv.dev/vulnerability/CVE-2026-39829 WEB
    https://osv.dev/vulnerability/CVE-2026-39830 WEB
    https://osv.dev/vulnerability/CVE-2026-39831 WEB
    https://osv.dev/vulnerability/CVE-2026-39832 WEB
    https://osv.dev/vulnerability/CVE-2026-39833 WEB
    https://osv.dev/vulnerability/CVE-2026-39834 WEB
    https://osv.dev/vulnerability/CVE-2026-39835 WEB
    https://osv.dev/vulnerability/CVE-2026-39836 WEB
    https://osv.dev/vulnerability/CVE-2026-39883 WEB
    https://osv.dev/vulnerability/CVE-2026-41178 WEB
    https://osv.dev/vulnerability/CVE-2026-42499 WEB
    https://osv.dev/vulnerability/CVE-2026-42504 WEB
    https://osv.dev/vulnerability/CVE-2026-42507 WEB
    https://osv.dev/vulnerability/CVE-2026-42508 WEB
    https://osv.dev/vulnerability/CVE-2026-46595 WEB
    https://osv.dev/vulnerability/CVE-2026-46597 WEB
    https://osv.dev/vulnerability/CVE-2026-46598 WEB
    https://osv.dev/vulnerability/CVE-2026-46600 WEB
    https://osv.dev/vulnerability/CVE-2026-56853 WEB
    https://osv.dev/vulnerability/CVE-2026-56858 WEB
    https://osv.dev/vulnerability/CVE-2026-56859 WEB
    https://osv.dev/vulnerability/CVE-2026-56860 WEB
    https://osv.dev/vulnerability/CVE-2026-56862 WEB
    https://osv.dev/vulnerability/CVE-2026-73500 WEB
    https://osv.dev/vulnerability/ghsa-259r-337f-4rfw WEB
    https://osv.dev/vulnerability/ghsa-gcjh-h69q-9w9g WEB
    https://osv.dev/vulnerability/ghsa-hrxh-6v49-42gf WEB
    https://osv.dev/vulnerability/ghsa-p77j-4mvh-x3m3 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-27145 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-29181 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-32280 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-32281 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-32282 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-32283 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-32288 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-32289 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-33186 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-33810 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-33811 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-33814 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-33818 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39820 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39821 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39823 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39825 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39826 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39827 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39828 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39829 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39830 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39831 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39832 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39833 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39834 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39835 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39836 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39883 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-41178 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42499 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42504 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42507 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42508 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-46595 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-46597 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-46598 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-46600 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56853 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56858 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56859 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56860 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56862 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-73500 WEB

    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "calico"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "3.30.7-r7"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Multiple security vulnerabilities affect the calico package. The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. See references for individual vulnerability details.",
      "id": "CLEANSTART-2026-YS01797",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-09-10T02:14:45.873622Z",
      "references": [
        {
          "type": "ADVISORY",
          "url": "https://github.com/cleanstart-dev/cleanstart-security-advisories/tree/main/advisories/2026/CLEANSTART-2026-YS01797.json"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-27145"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-29181"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-32280"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-32281"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-32282"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-32283"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-32288"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-32289"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-33186"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-33810"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-33811"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-33814"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-33818"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39820"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39821"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39823"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39825"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39826"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39827"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39828"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39829"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39830"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39831"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39832"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39833"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39834"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39835"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39836"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39883"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-41178"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42499"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42504"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42507"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42508"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-46595"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-46597"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-46598"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-46600"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56853"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56858"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56859"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56860"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56862"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-73500"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-259r-337f-4rfw"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-gcjh-h69q-9w9g"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-hrxh-6v49-42gf"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-p77j-4mvh-x3m3"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27145"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-29181"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32280"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32281"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32282"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32283"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32288"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32289"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33186"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33810"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33811"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33814"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33818"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39820"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39821"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39823"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39825"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39826"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39827"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39828"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39829"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39830"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39831"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39832"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39833"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39834"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39835"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39836"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39883"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41178"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42499"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42504"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42507"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42508"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46595"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46597"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46598"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46600"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56853"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56858"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56859"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56860"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56862"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-73500"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "severity": [
        {
          "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "type": "CVSS_V3"
        }
      ],
      "summary": "ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label",
      "upstream": [
        "CVE-2026-27145",
        "CVE-2026-29181",
        "CVE-2026-32280",
        "CVE-2026-32281",
        "CVE-2026-32282",
        "CVE-2026-32283",
        "CVE-2026-32288",
        "CVE-2026-32289",
        "CVE-2026-33186",
        "CVE-2026-33810",
        "CVE-2026-33811",
        "CVE-2026-33814",
        "CVE-2026-33818",
        "CVE-2026-39820",
        "CVE-2026-39821",
        "CVE-2026-39823",
        "CVE-2026-39825",
        "CVE-2026-39826",
        "CVE-2026-39827",
        "CVE-2026-39828",
        "CVE-2026-39829",
        "CVE-2026-39830",
        "CVE-2026-39831",
        "CVE-2026-39832",
        "CVE-2026-39833",
        "CVE-2026-39834",
        "CVE-2026-39835",
        "CVE-2026-39836",
        "CVE-2026-39883",
        "CVE-2026-41178",
        "CVE-2026-42499",
        "CVE-2026-42504",
        "CVE-2026-42507",
        "CVE-2026-42508",
        "CVE-2026-46595",
        "CVE-2026-46597",
        "CVE-2026-46598",
        "CVE-2026-46600",
        "CVE-2026-56853",
        "CVE-2026-56858",
        "CVE-2026-56859",
        "CVE-2026-56860",
        "CVE-2026-56862",
        "CVE-2026-73500",
        "ghsa-259r-337f-4rfw",
        "ghsa-gcjh-h69q-9w9g",
        "ghsa-hrxh-6v49-42gf",
        "ghsa-p77j-4mvh-x3m3"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-YZ14479 (CVE-2026-25681)

    Vulnerability from cleanstart – Published: 2026-09-18 00:47 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    gRPC-Go is the Go language implementation of gRPC
    Details

    Multiple security vulnerabilities affect the dex package. gRPC-Go is the Go language implementation of gRPC. See references for individual vulnerability details.

    References
    https://github.com/cleanstart-dev/cleanstart-secu… ADVISORY
    https://osv.dev/vulnerability/CVE-2026-25681 WEB
    https://osv.dev/vulnerability/CVE-2026-27136 WEB
    https://osv.dev/vulnerability/CVE-2026-29181 WEB
    https://osv.dev/vulnerability/CVE-2026-32952 WEB
    https://osv.dev/vulnerability/CVE-2026-33487 WEB
    https://osv.dev/vulnerability/CVE-2026-34986 WEB
    https://osv.dev/vulnerability/CVE-2026-39824 WEB
    https://osv.dev/vulnerability/CVE-2026-39828 WEB
    https://osv.dev/vulnerability/CVE-2026-39829 WEB
    https://osv.dev/vulnerability/CVE-2026-39830 WEB
    https://osv.dev/vulnerability/CVE-2026-39831 WEB
    https://osv.dev/vulnerability/CVE-2026-39832 WEB
    https://osv.dev/vulnerability/CVE-2026-39833 WEB
    https://osv.dev/vulnerability/CVE-2026-39834 WEB
    https://osv.dev/vulnerability/CVE-2026-39835 WEB
    https://osv.dev/vulnerability/CVE-2026-41178 WEB
    https://osv.dev/vulnerability/CVE-2026-42508 WEB
    https://osv.dev/vulnerability/CVE-2026-46595 WEB
    https://osv.dev/vulnerability/CVE-2026-46598 WEB
    https://osv.dev/vulnerability/CVE-2026-56852 WEB
    https://osv.dev/vulnerability/CVE-2026-56855 WEB
    https://osv.dev/vulnerability/CVE-2026-56864 WEB
    https://osv.dev/vulnerability/CVE-2026-56865 WEB
    https://osv.dev/vulnerability/CVE-2026-78662 WEB
    https://osv.dev/vulnerability/CVE-2026-84303 WEB
    https://osv.dev/vulnerability/CVE-2026-84304 WEB
    https://osv.dev/vulnerability/CVE-2026-84445 WEB
    https://osv.dev/vulnerability/ghsa-259r-337f-4rfw WEB
    https://osv.dev/vulnerability/ghsa-fw7p-63qq-7hpr WEB
    https://osv.dev/vulnerability/ghsa-hrxh-6v49-42gf WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-25681 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-27136 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-29181 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-32952 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-33487 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-34986 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39824 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39828 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39829 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39830 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39831 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39832 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39833 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39834 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39835 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-41178 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42508 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-46595 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-46598 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56852 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56855 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56864 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56865 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-78662 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-84303 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-84304 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-84445 WEB

    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "dex"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "2.42.1-r6"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Multiple security vulnerabilities affect the dex package. gRPC-Go is the Go language implementation of gRPC. See references for individual vulnerability details.",
      "id": "CLEANSTART-2026-YZ14479",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-09-18T00:47:58.234272Z",
      "references": [
        {
          "type": "ADVISORY",
          "url": "https://github.com/cleanstart-dev/cleanstart-security-advisories/tree/main/advisories/2026/CLEANSTART-2026-YZ14479.json"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-25681"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-27136"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-29181"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-32952"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-33487"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-34986"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39824"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39828"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39829"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39830"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39831"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39832"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39833"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39834"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39835"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-41178"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42508"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-46595"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-46598"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56852"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56855"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56864"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56865"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-78662"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-84303"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-84304"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-84445"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-259r-337f-4rfw"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-fw7p-63qq-7hpr"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-hrxh-6v49-42gf"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25681"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27136"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-29181"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32952"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33487"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-34986"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39824"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39828"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39829"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39830"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39831"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39832"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39833"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39834"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39835"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41178"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42508"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46595"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46598"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56852"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56855"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56864"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56865"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78662"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84303"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84304"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84445"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "severity": [
        {
          "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "type": "CVSS_V3"
        }
      ],
      "summary": "gRPC-Go is the Go language implementation of gRPC",
      "upstream": [
        "CVE-2026-25681",
        "CVE-2026-27136",
        "CVE-2026-29181",
        "CVE-2026-32952",
        "CVE-2026-33487",
        "CVE-2026-34986",
        "CVE-2026-39824",
        "CVE-2026-39828",
        "CVE-2026-39829",
        "CVE-2026-39830",
        "CVE-2026-39831",
        "CVE-2026-39832",
        "CVE-2026-39833",
        "CVE-2026-39834",
        "CVE-2026-39835",
        "CVE-2026-41178",
        "CVE-2026-42508",
        "CVE-2026-46595",
        "CVE-2026-46598",
        "CVE-2026-56852",
        "CVE-2026-56855",
        "CVE-2026-56864",
        "CVE-2026-56865",
        "CVE-2026-78662",
        "CVE-2026-84303",
        "CVE-2026-84304",
        "CVE-2026-84445",
        "ghsa-259r-337f-4rfw",
        "ghsa-fw7p-63qq-7hpr",
        "ghsa-hrxh-6v49-42gf"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-ZB65236 (CVE-2026-41178)

    Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    Security fixes in newrelic-infrastructure-agent 1.78.1-r1
    Details

    Package newrelic-infrastructure-agent version 1.78.1-r1 fixes 2 vulnerabilities: CVE-2026-41178, ghsa-259r-337f-4rfw


    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "newrelic-infrastructure-agent"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "1.78.1-r1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "1.78.1-r1"
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Package newrelic-infrastructure-agent version 1.78.1-r1 fixes 2 vulnerabilities: CVE-2026-41178, ghsa-259r-337f-4rfw",
      "id": "CLEANSTART-2026-ZB65236",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-09-01T11:17:16Z",
      "references": [
        {
          "type": "WEB",
          "url": "https://github.com/newrelic/infrastructure-agent"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "summary": "Security fixes in newrelic-infrastructure-agent 1.78.1-r1",
      "upstream": [
        "CVE-2026-41178",
        "ghsa-259r-337f-4rfw"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-ZB75097 (GHSA-259R-337F-4RFW)

    Vulnerability from cleanstart – Published: 2026-08-13 12:10 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    Security fixes in cortex 1.20.1-r3
    Details

    Package cortex version 1.20.1-r3 fixes 5 vulnerabilities: ghsa-259r-337f-4rfw, ghsa-3fxj-6jh8-hvhx, ghsa-9g5q-2w5x-hmxf, ghsa-rjr7-jggh-pgcp, CVE-2026-41178

    References

    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "cortex"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "1.20.1-r3"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "1.20.1-r3"
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Package cortex version 1.20.1-r3 fixes 5 vulnerabilities: ghsa-259r-337f-4rfw, ghsa-3fxj-6jh8-hvhx, ghsa-9g5q-2w5x-hmxf, ghsa-rjr7-jggh-pgcp, CVE-2026-41178",
      "id": "CLEANSTART-2026-ZB75097",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-08-13T12:10:09Z",
      "references": [
        {
          "type": "WEB",
          "url": "https://github.com/cortexproject/cortex"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "summary": "Security fixes in cortex 1.20.1-r3",
      "upstream": [
        "ghsa-259r-337f-4rfw",
        "ghsa-3fxj-6jh8-hvhx",
        "ghsa-9g5q-2w5x-hmxf",
        "ghsa-rjr7-jggh-pgcp",
        "CVE-2026-41178"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-ZG01398 (CVE-2026-33818)

    Vulnerability from cleanstart – Published: 2026-09-17 01:07 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    gRPC-Go is the Go language implementation of gRPC
    Details

    Multiple security vulnerabilities affect the terraform package. gRPC-Go is the Go language implementation of gRPC. See references for individual vulnerability details.

    References
    https://github.com/cleanstart-dev/cleanstart-secu… ADVISORY
    https://osv.dev/vulnerability/CVE-2026-33818 WEB
    https://osv.dev/vulnerability/CVE-2026-39821 WEB
    https://osv.dev/vulnerability/CVE-2026-41178 WEB
    https://osv.dev/vulnerability/CVE-2026-4660 WEB
    https://osv.dev/vulnerability/CVE-2026-46600 WEB
    https://osv.dev/vulnerability/CVE-2026-56853 WEB
    https://osv.dev/vulnerability/CVE-2026-56855 WEB
    https://osv.dev/vulnerability/CVE-2026-56858 WEB
    https://osv.dev/vulnerability/CVE-2026-56859 WEB
    https://osv.dev/vulnerability/CVE-2026-56860 WEB
    https://osv.dev/vulnerability/CVE-2026-56862 WEB
    https://osv.dev/vulnerability/CVE-2026-56864 WEB
    https://osv.dev/vulnerability/CVE-2026-56865 WEB
    https://osv.dev/vulnerability/CVE-2026-78662 WEB
    https://osv.dev/vulnerability/CVE-2026-84303 WEB
    https://osv.dev/vulnerability/CVE-2026-84304 WEB
    https://osv.dev/vulnerability/CVE-2026-84445 WEB
    https://osv.dev/vulnerability/ghsa-259r-337f-4rfw WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-33818 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39821 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-41178 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-4660 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-46600 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56853 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56855 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56858 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56859 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56860 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56862 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56864 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56865 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-78662 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-84303 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-84304 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-84445 WEB

    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "terraform"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "1.16.0-r2"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Multiple security vulnerabilities affect the terraform package. gRPC-Go is the Go language implementation of gRPC. See references for individual vulnerability details.",
      "id": "CLEANSTART-2026-ZG01398",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-09-17T01:07:19.033250Z",
      "references": [
        {
          "type": "ADVISORY",
          "url": "https://github.com/cleanstart-dev/cleanstart-security-advisories/tree/main/advisories/2026/CLEANSTART-2026-ZG01398.json"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-33818"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39821"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-41178"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-4660"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-46600"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56853"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56855"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56858"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56859"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56860"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56862"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56864"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56865"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-78662"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-84303"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-84304"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-84445"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-259r-337f-4rfw"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33818"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39821"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41178"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-4660"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46600"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56853"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56855"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56858"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56859"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56860"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56862"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56864"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56865"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78662"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84303"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84304"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84445"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "severity": [
        {
          "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "type": "CVSS_V3"
        }
      ],
      "summary": "gRPC-Go is the Go language implementation of gRPC",
      "upstream": [
        "CVE-2026-33818",
        "CVE-2026-39821",
        "CVE-2026-41178",
        "CVE-2026-4660",
        "CVE-2026-46600",
        "CVE-2026-56853",
        "CVE-2026-56855",
        "CVE-2026-56858",
        "CVE-2026-56859",
        "CVE-2026-56860",
        "CVE-2026-56862",
        "CVE-2026-56864",
        "CVE-2026-56865",
        "CVE-2026-78662",
        "CVE-2026-84303",
        "CVE-2026-84304",
        "CVE-2026-84445",
        "ghsa-259r-337f-4rfw"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-ZG59988 (CVE-2026-39821)

    Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    Security fixes in temporal-server 1.29.7-r1
    Details

    Package temporal-server version 1.29.7-r1 fixes 15 vulnerabilities: CVE-2026-39821, CVE-2026-33818, CVE-2026-46600, CVE-2026-56853, CVE-2026-56858...

    References

    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "temporal-server"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "1.29.7-r1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "1.29.7-r1"
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Package temporal-server version 1.29.7-r1 fixes 15 vulnerabilities: CVE-2026-39821, CVE-2026-33818, CVE-2026-46600, CVE-2026-56853, CVE-2026-56858...",
      "id": "CLEANSTART-2026-ZG59988",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-09-01T11:17:16Z",
      "references": [
        {
          "type": "WEB",
          "url": "https://github.com/temporalio/temporal"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "summary": "Security fixes in temporal-server 1.29.7-r1",
      "upstream": [
        "CVE-2026-39821",
        "CVE-2026-33818",
        "CVE-2026-46600",
        "CVE-2026-56853",
        "CVE-2026-56858",
        "CVE-2026-56859",
        "CVE-2026-56860",
        "CVE-2026-56862",
        "CVE-2026-5724",
        "CVE-2025-14987",
        "CVE-2025-14986",
        "CVE-2026-5199",
        "ghsa-hrxh-6v49-42gf",
        "ghsa-259r-337f-4rfw",
        "CVE-2026-41178"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-ZI93173 (CVE-2024-53259)

    Vulnerability from cleanstart – Published: 2026-09-10 01:32 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label
    Details

    Multiple security vulnerabilities affect the kubernetes-dns-node-cache package. The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. See references for individual vulnerability details.

    References
    https://github.com/cleanstart-dev/cleanstart-secu… ADVISORY
    https://osv.dev/vulnerability/CVE-2024-53259 WEB
    https://osv.dev/vulnerability/CVE-2025-47950 WEB
    https://osv.dev/vulnerability/CVE-2025-58063 WEB
    https://osv.dev/vulnerability/CVE-2025-59530 WEB
    https://osv.dev/vulnerability/CVE-2025-64702 WEB
    https://osv.dev/vulnerability/CVE-2025-68151 WEB
    https://osv.dev/vulnerability/CVE-2026-26017 WEB
    https://osv.dev/vulnerability/CVE-2026-26018 WEB
    https://osv.dev/vulnerability/CVE-2026-32934 WEB
    https://osv.dev/vulnerability/CVE-2026-32936 WEB
    https://osv.dev/vulnerability/CVE-2026-33190 WEB
    https://osv.dev/vulnerability/CVE-2026-33489 WEB
    https://osv.dev/vulnerability/CVE-2026-33818 WEB
    https://osv.dev/vulnerability/CVE-2026-35579 WEB
    https://osv.dev/vulnerability/CVE-2026-39821 WEB
    https://osv.dev/vulnerability/CVE-2026-39822 WEB
    https://osv.dev/vulnerability/CVE-2026-40898 WEB
    https://osv.dev/vulnerability/CVE-2026-42504 WEB
    https://osv.dev/vulnerability/CVE-2026-42505 WEB
    https://osv.dev/vulnerability/CVE-2026-46600 WEB
    https://osv.dev/vulnerability/CVE-2026-56852 WEB
    https://osv.dev/vulnerability/CVE-2026-56853 WEB
    https://osv.dev/vulnerability/CVE-2026-56858 WEB
    https://osv.dev/vulnerability/CVE-2026-56859 WEB
    https://osv.dev/vulnerability/CVE-2026-56860 WEB
    https://osv.dev/vulnerability/CVE-2026-56862 WEB
    https://osv.dev/vulnerability/CVE-2026-56864 WEB
    https://osv.dev/vulnerability/CVE-2026-56865 WEB
    https://osv.dev/vulnerability/ghsa-259r-337f-4rfw WEB
    https://osv.dev/vulnerability/ghsa-hrxh-6v49-42gf WEB
    https://nvd.nist.gov/vuln/detail/CVE-2024-53259 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-47950 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-58063 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-59530 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-64702 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2025-68151 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-26017 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-26018 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-32934 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-32936 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-33190 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-33489 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-33818 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-35579 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39821 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-39822 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-40898 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42504 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-42505 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-46600 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56852 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56853 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56858 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56859 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56860 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56862 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56864 WEB
    https://nvd.nist.gov/vuln/detail/CVE-2026-56865 WEB

    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "kubernetes-dns-node-cache"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "1.26.8-r5"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Multiple security vulnerabilities affect the kubernetes-dns-node-cache package. The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. See references for individual vulnerability details.",
      "id": "CLEANSTART-2026-ZI93173",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-09-10T01:32:39.433553Z",
      "references": [
        {
          "type": "ADVISORY",
          "url": "https://github.com/cleanstart-dev/cleanstart-security-advisories/tree/main/advisories/2026/CLEANSTART-2026-ZI93173.json"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2024-53259"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-47950"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-58063"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-59530"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-64702"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2025-68151"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-26017"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-26018"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-32934"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-32936"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-33190"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-33489"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-33818"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-35579"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39821"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-39822"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-40898"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42504"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-42505"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-46600"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56852"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56853"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56858"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56859"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56860"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56862"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56864"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/CVE-2026-56865"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-259r-337f-4rfw"
        },
        {
          "type": "WEB",
          "url": "https://osv.dev/vulnerability/ghsa-hrxh-6v49-42gf"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53259"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47950"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58063"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-59530"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-64702"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-68151"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-26017"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-26018"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32934"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32936"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33190"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33489"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33818"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-35579"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39821"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39822"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-40898"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42504"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42505"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46600"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56852"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56853"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56858"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56859"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56860"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56862"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56864"
        },
        {
          "type": "WEB",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56865"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "severity": [
        {
          "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "type": "CVSS_V3"
        }
      ],
      "summary": "ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label",
      "upstream": [
        "CVE-2024-53259",
        "CVE-2025-47950",
        "CVE-2025-58063",
        "CVE-2025-59530",
        "CVE-2025-64702",
        "CVE-2025-68151",
        "CVE-2026-26017",
        "CVE-2026-26018",
        "CVE-2026-32934",
        "CVE-2026-32936",
        "CVE-2026-33190",
        "CVE-2026-33489",
        "CVE-2026-33818",
        "CVE-2026-35579",
        "CVE-2026-39821",
        "CVE-2026-39822",
        "CVE-2026-40898",
        "CVE-2026-42504",
        "CVE-2026-42505",
        "CVE-2026-46600",
        "CVE-2026-56852",
        "CVE-2026-56853",
        "CVE-2026-56858",
        "CVE-2026-56859",
        "CVE-2026-56860",
        "CVE-2026-56862",
        "CVE-2026-56864",
        "CVE-2026-56865",
        "ghsa-259r-337f-4rfw",
        "ghsa-hrxh-6v49-42gf"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-ZS03179 (GHSA-259R-337F-4RFW)

    Vulnerability from cleanstart – Published: 2026-08-13 12:10 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    Security fixes in opentelemetry-collector-contrib 0.153.0-r3
    Details

    Package opentelemetry-collector-contrib version 0.153.0-r3 fixes 1 vulnerabilities: ghsa-259r-337f-4rfw


    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "opentelemetry-collector-contrib"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "0.153.0-r3"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "0.153.0-r3"
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Package opentelemetry-collector-contrib version 0.153.0-r3 fixes 1 vulnerabilities: ghsa-259r-337f-4rfw",
      "id": "CLEANSTART-2026-ZS03179",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-08-13T12:10:09Z",
      "references": [
        {
          "type": "WEB",
          "url": "https://github.com/open-telemetry/opentelemetry-collector-contrib"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "summary": "Security fixes in opentelemetry-collector-contrib 0.153.0-r3",
      "upstream": [
        "ghsa-259r-337f-4rfw"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-ZU67009 (CVE-2026-53492)

    Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    Security fixes in rancher-agent 2.14.3-r0
    Details

    Package rancher-agent version 2.14.3-r0 fixes 17 vulnerabilities: CVE-2026-53492, CVE-2026-50195, CVE-2026-46680, CVE-2026-53488, ghsa-hrxh-6v49-42gf...

    References

    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "rancher-agent"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "2.14.3-r0"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "2.14.3-r0"
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Package rancher-agent version 2.14.3-r0 fixes 17 vulnerabilities: CVE-2026-53492, CVE-2026-50195, CVE-2026-46680, CVE-2026-53488, ghsa-hrxh-6v49-42gf...",
      "id": "CLEANSTART-2026-ZU67009",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-09-01T11:17:16Z",
      "references": [
        {
          "type": "WEB",
          "url": "https://github.com/rancher/rancher"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "summary": "Security fixes in rancher-agent 2.14.3-r0",
      "upstream": [
        "CVE-2026-53492",
        "CVE-2026-50195",
        "CVE-2026-46680",
        "CVE-2026-53488",
        "ghsa-hrxh-6v49-42gf",
        "CVE-2026-56864",
        "CVE-2026-56865",
        "CVE-2026-48978",
        "CVE-2026-50163",
        "CVE-2026-50151",
        "CVE-2026-53489",
        "ghsa-gcjh-h69q-9w9g",
        "CVE-2026-47262",
        "CVE-2026-41178",
        "CVE-2026-50162",
        "ghsa-vh4v-2xq2-g5cg",
        "ghsa-259r-337f-4rfw"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CLEANSTART-2026-ZX66437 (GHSA-259R-337F-4RFW)

    Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source website
    Withdrawn 2026-09-18 VLAI
    Summary
    Security fixes in cadvisor 0.60.5-r0
    Details

    Package cadvisor version 0.60.5-r0 fixes 2 vulnerabilities: ghsa-259r-337f-4rfw, ghsa-hrxh-6v49-42gf

    References

    {
      "affected": [
        {
          "package": {
            "ecosystem": "CleanStart",
            "name": "cadvisor"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "0.60.5-r0"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "0.60.5-r0"
          ]
        }
      ],
      "credits": [],
      "database_specific": {},
      "details": "Package cadvisor version 0.60.5-r0 fixes 2 vulnerabilities: ghsa-259r-337f-4rfw, ghsa-hrxh-6v49-42gf",
      "id": "CLEANSTART-2026-ZX66437",
      "modified": "2026-09-18T11:59:01.768079Z",
      "published": "2026-09-01T11:17:16Z",
      "references": [
        {
          "type": "WEB",
          "url": "https://github.com/google/cadvisor"
        }
      ],
      "related": [],
      "schema_version": "1.7.3",
      "summary": "Security fixes in cadvisor 0.60.5-r0",
      "upstream": [
        "ghsa-259r-337f-4rfw",
        "ghsa-hrxh-6v49-42gf"
      ],
      "withdrawn": "2026-09-18T11:59:01.768079Z"
    }

    CVE-2026-63209 (GCVE-0-2026-63209)

    Vulnerability from cvelistv5 – Published: 2026-09-29 14:58 – Updated: 2026-09-29 16:32
    VLAI
    Title
    Integer Overflow or Wraparound and Out-of-bounds Write in compress
    Summary
    compress provides various compression algorithms. Prior to version 1.18.7, a signed integer overflow vulnerability in s2.NewDict() allows an attacker to bypass repeat index validation by supplying a dictionary with a uvarint-encoded repeat value exceeding MaxInt64. When Dict.Encode() is subsequently called, the overflowed negative repeat value causes an out-of-bounds memory access via unsafe.Pointer arithmetic, crashing the process with SIGSEGV. This issue has been patched in version 1.18.7.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-29 16:31 UTC
    CWE
    • CWE-190 - Integer Overflow or Wraparound
    • CWE-787 - Out-of-bounds Write
    Impacted products
    Vendor Product Version
    klauspost compress Affected: < 1.18.7
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-63209",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-29T16:31:39.668233Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-29T16:32:32.677Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "exploit"
                ],
                "url": "https://github.com/klauspost/compress/security/advisories/GHSA-259r-337f-4rfw"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "compress",
              "vendor": "klauspost",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 1.18.7"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "compress provides various compression algorithms. Prior to version 1.18.7, a signed integer overflow vulnerability in s2.NewDict() allows an attacker to bypass repeat index validation by supplying a dictionary with a uvarint-encoded repeat value exceeding MaxInt64. When Dict.Encode() is subsequently called, the overflowed negative repeat value causes an out-of-bounds memory access via unsafe.Pointer arithmetic, crashing the process with SIGSEGV. This issue has been patched in version 1.18.7."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-190",
                  "description": "CWE-190: Integer Overflow or Wraparound",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-787",
                  "description": "CWE-787: Out-of-bounds Write",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-29T14:58:53.366Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/klauspost/compress/security/advisories/GHSA-259r-337f-4rfw",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/klauspost/compress/security/advisories/GHSA-259r-337f-4rfw"
            },
            {
              "name": "https://github.com/klauspost/compress/commit/539243b8823ee8f03e49969823d57c348c917536",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/klauspost/compress/commit/539243b8823ee8f03e49969823d57c348c917536"
            },
            {
              "name": "https://github.com/klauspost/compress/releases/tag/v1.18.7",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/klauspost/compress/releases/tag/v1.18.7"
            }
          ],
          "source": {
            "advisory": "GHSA-259r-337f-4rfw",
            "discovery": "UNKNOWN"
          },
          "title": "Integer Overflow or Wraparound and Out-of-bounds Write in compress"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2026-63209",
        "datePublished": "2026-09-29T14:58:53.366Z",
        "dateReserved": "2026-07-15T22:19:06.906Z",
        "dateUpdated": "2026-09-29T16:32:32.677Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }