Find a vulnerability
Search criteria
Related vulnerabilities
CLEANSTART-2026-AE16267 (CVE-2025-47912)
Vulnerability from cleanstart – Published: 2026-09-08 01:48 – Updated: 2026-09-18 11:59 – Source websiteMultiple security vulnerabilities affect the step package. gRPC-Go is the Go language implementation of gRPC. See references for individual vulnerability details.
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "step"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.30.6-r5"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"credits": [],
"database_specific": {},
"details": "Multiple security vulnerabilities affect the step package. gRPC-Go is the Go language implementation of gRPC. See references for individual vulnerability details.",
"id": "CLEANSTART-2026-AE16267",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-09-08T01:48:50.081347Z",
"references": [
{
"type": "ADVISORY",
"url": "https://github.com/cleanstart-dev/cleanstart-security-advisories/tree/main/advisories/2026/CLEANSTART-2026-AE16267.json"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-47912"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-58183"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-58185"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-58186"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-58187"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-58188"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-58189"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-61723"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-61724"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-61725"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-61729"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-62820"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-33186"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-33818"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39821"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39822"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42505"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-46600"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56852"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56853"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56855"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56858"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56859"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56860"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56862"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-78662"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-84304"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-259r-337f-4rfw"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-hrxh-6v49-42gf"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47912"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58183"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58185"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58186"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58187"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58188"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58189"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61723"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61724"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61725"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61729"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-62820"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33186"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33818"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39821"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39822"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42505"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46600"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56852"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56853"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56855"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56858"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56859"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56860"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56862"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78662"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84304"
}
],
"related": [],
"schema_version": "1.7.3",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"type": "CVSS_V3"
}
],
"summary": "gRPC-Go is the Go language implementation of gRPC",
"upstream": [
"CVE-2025-47912",
"CVE-2025-58183",
"CVE-2025-58185",
"CVE-2025-58186",
"CVE-2025-58187",
"CVE-2025-58188",
"CVE-2025-58189",
"CVE-2025-61723",
"CVE-2025-61724",
"CVE-2025-61725",
"CVE-2025-61729",
"CVE-2025-62820",
"CVE-2026-33186",
"CVE-2026-33818",
"CVE-2026-39821",
"CVE-2026-39822",
"CVE-2026-42505",
"CVE-2026-46600",
"CVE-2026-56852",
"CVE-2026-56853",
"CVE-2026-56855",
"CVE-2026-56858",
"CVE-2026-56859",
"CVE-2026-56860",
"CVE-2026-56862",
"CVE-2026-78662",
"CVE-2026-84304",
"ghsa-259r-337f-4rfw",
"ghsa-hrxh-6v49-42gf"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-AH15669 (GHSA-259R-337F-4RFW)
Vulnerability from cleanstart – Published: 2026-09-30 20:34 – Updated: 2026-08-21 12:59 – Source websiteghsa-259r-337f-4rfw affects multiple packages. This issue is resolved in later releases. See references for individual vulnerability details.
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "crane"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.19.2-r1"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "crane"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.20.7-r3"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "crane"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.20.7-r4"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"credits": [],
"database_specific": {},
"details": "ghsa-259r-337f-4rfw affects multiple packages. This issue is resolved in later releases. See references for individual vulnerability details.",
"id": "CLEANSTART-2026-AH15669",
"modified": "2026-08-21T12:59:12Z",
"published": "2026-09-30T20:34:53.118246Z",
"references": [
{
"type": "ADVISORY",
"url": "https://github.com/cleanstart-dev/cleanstart-security-advisories/tree/main/advisories/2026/CLEANSTART-2026-AH15669.json"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-259r-337f-4rfw"
}
],
"related": [],
"schema_version": "1.7.3",
"summary": "Security fix for ghsa-259r-337f-4rfw applied in: crane 0.19.2-r1, crane 0.20.7-r3, crane 0.20.7-r4",
"upstream": [
"ghsa-259r-337f-4rfw"
]
}
CLEANSTART-2026-AJ39907 (CVE-2025-47912)
Vulnerability from cleanstart – Published: 2026-09-08 01:55 – Updated: 2026-09-18 11:59 – Source websiteMultiple security vulnerabilities affect the step package. gRPC-Go is the Go language implementation of gRPC. See references for individual vulnerability details.
| URL | Type | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "step"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.29.0-r5"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"credits": [],
"database_specific": {},
"details": "Multiple security vulnerabilities affect the step package. gRPC-Go is the Go language implementation of gRPC. See references for individual vulnerability details.",
"id": "CLEANSTART-2026-AJ39907",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-09-08T01:55:49.714182Z",
"references": [
{
"type": "ADVISORY",
"url": "https://github.com/cleanstart-dev/cleanstart-security-advisories/tree/main/advisories/2026/CLEANSTART-2026-AJ39907.json"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-47912"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-58183"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-58185"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-58186"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-58187"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-58188"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-58189"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-61723"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-61724"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-61725"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-61729"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-62820"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-69725"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-25793"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-26958"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-29181"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-30836"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-33815"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-33816"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-33818"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-34986"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39821"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39822"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-40097"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-41178"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-41889"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42505"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-46600"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56853"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56855"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56858"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56859"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56860"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56862"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-78662"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-84304"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-259r-337f-4rfw"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-3fxj-6jh8-hvhx"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-9g5q-2w5x-hmxf"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-hrxh-6v49-42gf"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-mpwr-8vm7-h73f"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-rjr7-jggh-pgcp"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47912"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58183"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58185"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58186"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58187"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58188"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58189"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61723"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61724"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61725"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61729"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-62820"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-69725"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25793"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-26958"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-29181"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-30836"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33815"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33816"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33818"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-34986"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39821"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39822"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-40097"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41178"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41889"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42505"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46600"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56853"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56855"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56858"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56859"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56860"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56862"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78662"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84304"
}
],
"related": [],
"schema_version": "1.7.3",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"type": "CVSS_V3"
}
],
"summary": "gRPC-Go is the Go language implementation of gRPC",
"upstream": [
"CVE-2025-47912",
"CVE-2025-58183",
"CVE-2025-58185",
"CVE-2025-58186",
"CVE-2025-58187",
"CVE-2025-58188",
"CVE-2025-58189",
"CVE-2025-61723",
"CVE-2025-61724",
"CVE-2025-61725",
"CVE-2025-61729",
"CVE-2025-62820",
"CVE-2025-69725",
"CVE-2026-25793",
"CVE-2026-26958",
"CVE-2026-29181",
"CVE-2026-30836",
"CVE-2026-33815",
"CVE-2026-33816",
"CVE-2026-33818",
"CVE-2026-34986",
"CVE-2026-39821",
"CVE-2026-39822",
"CVE-2026-40097",
"CVE-2026-41178",
"CVE-2026-41889",
"CVE-2026-42505",
"CVE-2026-46600",
"CVE-2026-56853",
"CVE-2026-56855",
"CVE-2026-56858",
"CVE-2026-56859",
"CVE-2026-56860",
"CVE-2026-56862",
"CVE-2026-78662",
"CVE-2026-84304",
"ghsa-259r-337f-4rfw",
"ghsa-3fxj-6jh8-hvhx",
"ghsa-9g5q-2w5x-hmxf",
"ghsa-hrxh-6v49-42gf",
"ghsa-mpwr-8vm7-h73f",
"ghsa-rjr7-jggh-pgcp"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-AJ83096 (CVE-2025-47912)
Vulnerability from cleanstart – Published: 2026-09-10 01:08 – Updated: 2026-09-18 11:59 – Source websiteMultiple security vulnerabilities affect the logstash-exporter package. Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsing deeply-nested, recursive structures. See references for individual vulnerability details.
| URL | Type | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "logstash-exporter"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.9.1-r2"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"credits": [],
"database_specific": {},
"details": "Multiple security vulnerabilities affect the logstash-exporter package. Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsing deeply-nested, recursive structures. See references for individual vulnerability details.",
"id": "CLEANSTART-2026-AJ83096",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-09-10T01:08:37.435444Z",
"references": [
{
"type": "ADVISORY",
"url": "https://github.com/cleanstart-dev/cleanstart-security-advisories/tree/main/advisories/2026/CLEANSTART-2026-AJ83096.json"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-47912"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-58183"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-58185"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-58186"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-58187"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-58188"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-58189"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-61723"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-61724"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-61725"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-61729"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-68121"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-32283"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-33818"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39820"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39821"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39822"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39824"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39836"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42499"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42505"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-46600"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56853"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56858"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56859"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56860"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56862"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-259r-337f-4rfw"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47912"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58183"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58185"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58186"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58187"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58188"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58189"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61723"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61724"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61725"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61729"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-68121"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32283"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33818"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39820"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39821"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39822"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39824"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39836"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42499"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42505"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46600"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56853"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56858"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56859"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56860"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56862"
}
],
"related": [],
"schema_version": "1.7.3",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"type": "CVSS_V3"
}
],
"summary": "Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsing deeply-nested, recursive structures",
"upstream": [
"CVE-2025-47912",
"CVE-2025-58183",
"CVE-2025-58185",
"CVE-2025-58186",
"CVE-2025-58187",
"CVE-2025-58188",
"CVE-2025-58189",
"CVE-2025-61723",
"CVE-2025-61724",
"CVE-2025-61725",
"CVE-2025-61729",
"CVE-2025-68121",
"CVE-2026-32283",
"CVE-2026-33818",
"CVE-2026-39820",
"CVE-2026-39821",
"CVE-2026-39822",
"CVE-2026-39824",
"CVE-2026-39836",
"CVE-2026-42499",
"CVE-2026-42505",
"CVE-2026-46600",
"CVE-2026-56853",
"CVE-2026-56858",
"CVE-2026-56859",
"CVE-2026-56860",
"CVE-2026-56862",
"ghsa-259r-337f-4rfw"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-AQ94704 (CVE-2024-51744)
Vulnerability from cleanstart – Published: 2026-09-15 01:00 – Updated: 2026-09-18 11:59 – Source websiteMultiple security vulnerabilities affect the minio-operator package. Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. See references for individual vulnerability details.
| URL | Type | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "minio-operator"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "7.1.1-r5"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"credits": [],
"database_specific": {},
"details": "Multiple security vulnerabilities affect the minio-operator package. Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. See references for individual vulnerability details.",
"id": "CLEANSTART-2026-AQ94704",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-09-15T01:00:17.233996Z",
"references": [
{
"type": "ADVISORY",
"url": "https://github.com/cleanstart-dev/cleanstart-security-advisories/tree/main/advisories/2026/CLEANSTART-2026-AQ94704.json"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2024-51744"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-30204"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-47912"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-58183"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-58185"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-58186"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-58187"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-58188"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-58189"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-61723"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-61724"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-61725"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-61726"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-61727"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-61728"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-61729"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-61730"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-61731"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-61732"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-68119"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-68121"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-25679"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-25680"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-27139"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-27142"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-27145"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-33814"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-33818"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39821"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39833"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39836"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42499"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42504"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42507"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42508"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-46595"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-46600"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56853"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56855"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56858"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56859"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56860"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56862"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56864"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56865"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-78662"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-259r-337f-4rfw"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-29wx-vh33-7x7r"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-f6x5-jh6r-wrfv"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-j5w8-q4qc-rx2x"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-mh63-6h87-95cp"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-p436-gjf2-799p"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51744"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30204"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47912"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58183"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58185"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58186"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58187"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58188"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58189"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61723"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61724"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61725"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61726"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61727"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61728"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61729"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61730"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61731"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61732"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-68119"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-68121"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25679"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25680"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27139"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27142"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27145"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33814"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33818"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39821"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39833"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39836"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42499"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42504"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42507"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42508"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46595"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46600"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56853"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56855"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56858"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56859"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56860"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56862"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56864"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56865"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78662"
}
],
"related": [],
"schema_version": "1.7.3",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"type": "CVSS_V3"
}
],
"summary": "Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection",
"upstream": [
"CVE-2024-51744",
"CVE-2025-30204",
"CVE-2025-47912",
"CVE-2025-58183",
"CVE-2025-58185",
"CVE-2025-58186",
"CVE-2025-58187",
"CVE-2025-58188",
"CVE-2025-58189",
"CVE-2025-61723",
"CVE-2025-61724",
"CVE-2025-61725",
"CVE-2025-61726",
"CVE-2025-61727",
"CVE-2025-61728",
"CVE-2025-61729",
"CVE-2025-61730",
"CVE-2025-61731",
"CVE-2025-61732",
"CVE-2025-68119",
"CVE-2025-68121",
"CVE-2026-25679",
"CVE-2026-25680",
"CVE-2026-27139",
"CVE-2026-27142",
"CVE-2026-27145",
"CVE-2026-33814",
"CVE-2026-33818",
"CVE-2026-39821",
"CVE-2026-39833",
"CVE-2026-39836",
"CVE-2026-42499",
"CVE-2026-42504",
"CVE-2026-42507",
"CVE-2026-42508",
"CVE-2026-46595",
"CVE-2026-46600",
"CVE-2026-56853",
"CVE-2026-56855",
"CVE-2026-56858",
"CVE-2026-56859",
"CVE-2026-56860",
"CVE-2026-56862",
"CVE-2026-56864",
"CVE-2026-56865",
"CVE-2026-78662",
"ghsa-259r-337f-4rfw",
"ghsa-29wx-vh33-7x7r",
"ghsa-f6x5-jh6r-wrfv",
"ghsa-j5w8-q4qc-rx2x",
"ghsa-mh63-6h87-95cp",
"ghsa-p436-gjf2-799p"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-AT65598 (GHSA-HRXH-6V49-42GF)
Vulnerability from cleanstart – Published: 2026-07-30 07:10 – Updated: 2026-09-18 11:59 – Source websitePackage rclone version 1.74.3-r2 fixes 5 vulnerabilities: ghsa-hrxh-6v49-42gf, ghsa-259r-337f-4rfw, ghsa-3fxj-6jh8-hvhx, ghsa-9g5q-2w5x-hmxf, ghsa-rjr7-jggh-pgcp
| URL | Type | |
|---|---|---|
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "rclone"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.74.3-r2"
}
],
"type": "ECOSYSTEM"
}
],
"versions": [
"1.74.3-r2"
]
}
],
"credits": [],
"database_specific": {},
"details": "Package rclone version 1.74.3-r2 fixes 5 vulnerabilities: ghsa-hrxh-6v49-42gf, ghsa-259r-337f-4rfw, ghsa-3fxj-6jh8-hvhx, ghsa-9g5q-2w5x-hmxf, ghsa-rjr7-jggh-pgcp",
"id": "CLEANSTART-2026-AT65598",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-07-30T07:10:53Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/rclone/rclone"
}
],
"related": [],
"schema_version": "1.7.3",
"summary": "Security fixes in rclone 1.74.3-r2",
"upstream": [
"ghsa-hrxh-6v49-42gf",
"ghsa-259r-337f-4rfw",
"ghsa-3fxj-6jh8-hvhx",
"ghsa-9g5q-2w5x-hmxf",
"ghsa-rjr7-jggh-pgcp"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-AW13171 (GHSA-HRXH-6V49-42GF)
Vulnerability from cleanstart – Published: 2026-07-30 07:10 – Updated: 2026-09-18 11:59 – Source websitePackage rclone version 1.72.1-r11 fixes 5 vulnerabilities: ghsa-hrxh-6v49-42gf, ghsa-259r-337f-4rfw, ghsa-3fxj-6jh8-hvhx, ghsa-9g5q-2w5x-hmxf, ghsa-rjr7-jggh-pgcp
| URL | Type | |
|---|---|---|
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "rclone"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.72.1-r11"
}
],
"type": "ECOSYSTEM"
}
],
"versions": [
"1.72.1-r11"
]
}
],
"credits": [],
"database_specific": {},
"details": "Package rclone version 1.72.1-r11 fixes 5 vulnerabilities: ghsa-hrxh-6v49-42gf, ghsa-259r-337f-4rfw, ghsa-3fxj-6jh8-hvhx, ghsa-9g5q-2w5x-hmxf, ghsa-rjr7-jggh-pgcp",
"id": "CLEANSTART-2026-AW13171",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-07-30T07:10:53Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/rclone/rclone"
}
],
"related": [],
"schema_version": "1.7.3",
"summary": "Security fixes in rclone 1.72.1-r11",
"upstream": [
"ghsa-hrxh-6v49-42gf",
"ghsa-259r-337f-4rfw",
"ghsa-3fxj-6jh8-hvhx",
"ghsa-9g5q-2w5x-hmxf",
"ghsa-rjr7-jggh-pgcp"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-AW19890 (GHSA-259R-337F-4RFW)
Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source websitePackage prometheus-statsd-exporter version 0.27.2-r1 fixes 10 vulnerabilities: ghsa-259r-337f-4rfw, CVE-2026-39821, CVE-2026-56860, CVE-2026-56858, CVE-2026-33818...
| URL | Type | |
|---|---|---|
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "prometheus-statsd-exporter"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.27.2-r1"
}
],
"type": "ECOSYSTEM"
}
],
"versions": [
"0.27.2-r1"
]
}
],
"credits": [],
"database_specific": {},
"details": "Package prometheus-statsd-exporter version 0.27.2-r1 fixes 10 vulnerabilities: ghsa-259r-337f-4rfw, CVE-2026-39821, CVE-2026-56860, CVE-2026-56858, CVE-2026-33818...",
"id": "CLEANSTART-2026-AW19890",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-09-01T11:17:16Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/prometheus/statsd_exporter"
}
],
"related": [],
"schema_version": "1.7.3",
"summary": "Security fixes in prometheus-statsd-exporter 0.27.2-r1",
"upstream": [
"ghsa-259r-337f-4rfw",
"CVE-2026-39821",
"CVE-2026-56860",
"CVE-2026-56858",
"CVE-2026-33818",
"CVE-2026-46600",
"CVE-2026-56853",
"CVE-2026-56859",
"CVE-2026-56862",
"CVE-2026-39821"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-AY98693 (GHSA-259R-337F-4RFW)
Vulnerability from cleanstart – Published: 2026-07-30 07:10 – Updated: 2026-09-18 11:59 – Source websitePackage elastic-beats version 9.2.8-r7 fixes 2 vulnerabilities: ghsa-259r-337f-4rfw, CVE-2026-41178
| URL | Type | |
|---|---|---|
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "elastic-beats"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "9.2.8-r7"
}
],
"type": "ECOSYSTEM"
}
],
"versions": [
"9.2.8-r7"
]
}
],
"credits": [],
"database_specific": {},
"details": "Package elastic-beats version 9.2.8-r7 fixes 2 vulnerabilities: ghsa-259r-337f-4rfw, CVE-2026-41178",
"id": "CLEANSTART-2026-AY98693",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-07-30T07:10:53Z",
"references": [
{
"type": "WEB",
"url": "https://www.elastic.co/products/beats"
}
],
"related": [],
"schema_version": "1.7.3",
"summary": "Security fixes in elastic-beats 9.2.8-r7",
"upstream": [
"ghsa-259r-337f-4rfw",
"CVE-2026-41178"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-BA26255 (CVE-2026-26958)
Vulnerability from cleanstart – Published: 2026-09-10 01:49 – Updated: 2026-09-18 11:59 – Source websiteMultiple security vulnerabilities affect the dex package. filippo. See references for individual vulnerability details.
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "dex"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "2.42.1-r2"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"credits": [],
"database_specific": {},
"details": "Multiple security vulnerabilities affect the dex package. filippo. See references for individual vulnerability details.",
"id": "CLEANSTART-2026-BA26255",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-09-10T01:49:39.942504Z",
"references": [
{
"type": "ADVISORY",
"url": "https://github.com/cleanstart-dev/cleanstart-security-advisories/tree/main/advisories/2026/CLEANSTART-2026-BA26255.json"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-26958"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-259r-337f-4rfw"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-fw7p-63qq-7hpr"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-26958"
}
],
"related": [],
"schema_version": "1.7.3",
"summary": "filippo",
"upstream": [
"CVE-2026-26958",
"ghsa-259r-337f-4rfw",
"ghsa-fw7p-63qq-7hpr"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-BB29139 (GHSA-259R-337F-4RFW)
Vulnerability from cleanstart – Published: 2026-08-13 12:10 – Updated: 2026-09-18 11:59 – Source websitePackage rabbitmq-messaging-topology-operator version 1.16.0-r2 fixes 1 vulnerabilities: ghsa-259r-337f-4rfw
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "rabbitmq-messaging-topology-operator"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.16.0-r2"
}
],
"type": "ECOSYSTEM"
}
],
"versions": [
"1.16.0-r2"
]
}
],
"credits": [],
"database_specific": {},
"details": "Package rabbitmq-messaging-topology-operator version 1.16.0-r2 fixes 1 vulnerabilities: ghsa-259r-337f-4rfw",
"id": "CLEANSTART-2026-BB29139",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-08-13T12:10:09Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/rabbitmq/messaging-topology-operator"
}
],
"related": [],
"schema_version": "1.7.3",
"summary": "Security fixes in rabbitmq-messaging-topology-operator 1.16.0-r2",
"upstream": [
"ghsa-259r-337f-4rfw"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-BE07554 (CVE-2026-2303)
Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source websitePackage karma version 0.129-r1 fixes 6 vulnerabilities: CVE-2026-2303, CVE-2026-39824, ghsa-259r-337f-4rfw, ghsa-3fxj-6jh8-hvhx, ghsa-9g5q-2w5x-hmxf...
| URL | Type | |
|---|---|---|
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "karma"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.129-r1"
}
],
"type": "ECOSYSTEM"
}
],
"versions": [
"0.129-r1"
]
}
],
"credits": [],
"database_specific": {},
"details": "Package karma version 0.129-r1 fixes 6 vulnerabilities: CVE-2026-2303, CVE-2026-39824, ghsa-259r-337f-4rfw, ghsa-3fxj-6jh8-hvhx, ghsa-9g5q-2w5x-hmxf...",
"id": "CLEANSTART-2026-BE07554",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-09-01T11:17:16Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/prymitive/karma.git"
}
],
"related": [],
"schema_version": "1.7.3",
"summary": "Security fixes in karma 0.129-r1",
"upstream": [
"CVE-2026-2303",
"CVE-2026-39824",
"ghsa-259r-337f-4rfw",
"ghsa-3fxj-6jh8-hvhx",
"ghsa-9g5q-2w5x-hmxf",
"ghsa-rjr7-jggh-pgcp"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-BE94448 (GHSA-259R-337F-4RFW)
Vulnerability from cleanstart – Published: 2026-08-13 12:10 – Updated: 2026-09-18 11:59 – Source websitePackage nats-streaming version 0.23.2-r1 fixes 1 vulnerabilities: ghsa-259r-337f-4rfw
| URL | Type | |
|---|---|---|
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "nats-streaming"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.23.2-r1"
}
],
"type": "ECOSYSTEM"
}
],
"versions": [
"0.23.2-r1"
]
}
],
"credits": [],
"database_specific": {},
"details": "Package nats-streaming version 0.23.2-r1 fixes 1 vulnerabilities: ghsa-259r-337f-4rfw",
"id": "CLEANSTART-2026-BE94448",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-08-13T12:10:09Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/nats-io/nats-streaming-server"
}
],
"related": [],
"schema_version": "1.7.3",
"summary": "Security fixes in nats-streaming 0.23.2-r1",
"upstream": [
"ghsa-259r-337f-4rfw"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-BR58082 (CVE-2023-42821)
Vulnerability from cleanstart – Published: 2026-09-10 02:53 – Updated: 2026-09-18 11:59 – Source websiteMultiple security vulnerabilities affect the kube-metrics-adapter package. Echo is a Go web framework. See references for individual vulnerability details.
| URL | Type | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "kube-metrics-adapter"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.2.9-r2"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"credits": [],
"database_specific": {},
"details": "Multiple security vulnerabilities affect the kube-metrics-adapter package. Echo is a Go web framework. See references for individual vulnerability details.",
"id": "CLEANSTART-2026-BR58082",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-09-10T02:53:42.246802Z",
"references": [
{
"type": "ADVISORY",
"url": "https://github.com/cleanstart-dev/cleanstart-security-advisories/tree/main/advisories/2026/CLEANSTART-2026-BR58082.json"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2023-42821"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-33818"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39821"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-40890"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-40898"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-41178"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-46600"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-55677"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56853"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56858"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56859"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56860"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56862"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-73500"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-259r-337f-4rfw"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-gcjh-h69q-9w9g"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-hrxh-6v49-42gf"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-42821"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33818"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39821"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-40890"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-40898"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41178"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46600"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-55677"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56853"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56858"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56859"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56860"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56862"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-73500"
}
],
"related": [],
"schema_version": "1.7.3",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"type": "CVSS_V3"
}
],
"summary": "Echo is a Go web framework",
"upstream": [
"CVE-2023-42821",
"CVE-2026-33818",
"CVE-2026-39821",
"CVE-2026-40890",
"CVE-2026-40898",
"CVE-2026-41178",
"CVE-2026-46600",
"CVE-2026-55677",
"CVE-2026-56853",
"CVE-2026-56858",
"CVE-2026-56859",
"CVE-2026-56860",
"CVE-2026-56862",
"CVE-2026-73500",
"ghsa-259r-337f-4rfw",
"ghsa-gcjh-h69q-9w9g",
"ghsa-hrxh-6v49-42gf"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-BT15862 (GHSA-259R-337F-4RFW)
Vulnerability from cleanstart – Published: 2026-08-13 12:10 – Updated: 2026-09-18 11:59 – Source websitePackage ollama-fips version 0.30.11-r2 fixes 1 vulnerabilities: ghsa-259r-337f-4rfw
| URL | Type | |
|---|---|---|
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "ollama-fips"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.30.11-r2"
}
],
"type": "ECOSYSTEM"
}
],
"versions": [
"0.30.11-r2"
]
}
],
"credits": [],
"database_specific": {},
"details": "Package ollama-fips version 0.30.11-r2 fixes 1 vulnerabilities: ghsa-259r-337f-4rfw",
"id": "CLEANSTART-2026-BT15862",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-08-13T12:10:09Z",
"references": [
{
"type": "WEB",
"url": "https://ollama.com"
}
],
"related": [],
"schema_version": "1.7.3",
"summary": "Security fixes in ollama-fips 0.30.11-r2",
"upstream": [
"ghsa-259r-337f-4rfw"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-BY91066 (CVE-2025-15558)
Vulnerability from cleanstart – Published: 2026-09-08 02:00 – Updated: 2026-09-18 11:59 – Source websiteMultiple security vulnerabilities affect the dynatrace-operator package. A malicious GOSUMDB was capable of serving arbitrary module content not contained within the transparency log. See references for individual vulnerability details.
| URL | Type | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "dynatrace-operator"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.8.1-r5"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"credits": [],
"database_specific": {},
"details": "Multiple security vulnerabilities affect the dynatrace-operator package. A malicious GOSUMDB was capable of serving arbitrary module content not contained within the transparency log. See references for individual vulnerability details.",
"id": "CLEANSTART-2026-BY91066",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-09-08T02:00:36.015974Z",
"references": [
{
"type": "ADVISORY",
"url": "https://github.com/cleanstart-dev/cleanstart-security-advisories/tree/main/advisories/2026/CLEANSTART-2026-BY91066.json"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-15558"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-33818"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39821"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39822"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-41178"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42504"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42505"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-46600"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56852"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56859"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56864"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-259r-337f-4rfw"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-15558"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33818"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39821"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39822"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41178"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42504"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42505"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46600"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56852"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56859"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56864"
}
],
"related": [],
"schema_version": "1.7.3",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"type": "CVSS_V3"
}
],
"summary": "malicious GOSUMDB was capable of serving arbitrary module content not contained within the transparency log",
"upstream": [
"CVE-2025-15558",
"CVE-2026-33818",
"CVE-2026-39821",
"CVE-2026-39822",
"CVE-2026-41178",
"CVE-2026-42504",
"CVE-2026-42505",
"CVE-2026-46600",
"CVE-2026-56852",
"CVE-2026-56859",
"CVE-2026-56864",
"ghsa-259r-337f-4rfw"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-CD03295 (CVE-2026-53492)
Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source websitePackage rancher-agent version 2.11.15-r1 fixes 28 vulnerabilities: CVE-2026-53492, CVE-2026-50195, CVE-2026-53489, CVE-2024-40635, CVE-2024-25621...
| URL | Type | |
|---|---|---|
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "rancher-agent"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "2.11.15-r1"
}
],
"type": "ECOSYSTEM"
}
],
"versions": [
"2.11.15-r1"
]
}
],
"credits": [],
"database_specific": {},
"details": "Package rancher-agent version 2.11.15-r1 fixes 28 vulnerabilities: CVE-2026-53492, CVE-2026-50195, CVE-2026-53489, CVE-2024-40635, CVE-2024-25621...",
"id": "CLEANSTART-2026-CD03295",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-09-01T11:17:16Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/rancher/rancher"
}
],
"related": [],
"schema_version": "1.7.3",
"summary": "Security fixes in rancher-agent 2.11.15-r1",
"upstream": [
"CVE-2026-53492",
"CVE-2026-50195",
"CVE-2026-53489",
"CVE-2024-40635",
"CVE-2024-25621",
"CVE-2025-64329",
"CVE-2024-41110",
"CVE-2026-33997",
"CVE-2026-41567",
"CVE-2026-42306",
"CVE-2026-41568",
"CVE-2025-15558",
"CVE-2024-29018",
"CVE-2024-24557",
"CVE-2026-34040",
"CVE-2025-54410",
"ghsa-hrxh-6v49-42gf",
"CVE-2026-56864",
"CVE-2026-56865",
"CVE-2026-56852",
"CVE-2026-48978",
"CVE-2026-50151",
"CVE-2026-50163",
"CVE-2026-50162",
"ghsa-vh4v-2xq2-g5cg",
"ghsa-gcjh-h69q-9w9g",
"CVE-2026-41178",
"ghsa-259r-337f-4rfw"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-CN27602 (CVE-2025-15558)
Vulnerability from cleanstart – Published: 2026-09-15 01:05 – Updated: 2026-09-18 11:59 – Source websiteMultiple security vulnerabilities affect the minio-operator package. Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. See references for individual vulnerability details.
| URL | Type | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "minio-operator"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "7.1.1-r5"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"credits": [],
"database_specific": {},
"details": "Multiple security vulnerabilities affect the minio-operator package. Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. See references for individual vulnerability details.",
"id": "CLEANSTART-2026-CN27602",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-09-15T01:05:42.370597Z",
"references": [
{
"type": "ADVISORY",
"url": "https://github.com/cleanstart-dev/cleanstart-security-advisories/tree/main/advisories/2026/CLEANSTART-2026-CN27602.json"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-15558"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-22868"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-30204"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-47912"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-58183"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-58185"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-58186"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-58187"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-58188"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-58189"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-61723"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-61724"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-61725"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-61726"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-61727"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-61728"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-61729"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-61730"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-61731"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-61732"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-68119"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-68121"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-25679"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-25680"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-27139"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-27142"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-27145"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-33814"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-33818"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39821"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39822"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39833"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39836"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42499"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42504"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42505"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42507"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42508"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-46595"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-46600"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56852"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56853"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56855"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56858"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56859"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56860"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56862"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56864"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56865"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-78662"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-259r-337f-4rfw"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-6v2p-p543-phr9"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-f6x5-jh6r-wrfv"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-j5w8-q4qc-rx2x"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-p436-gjf2-799p"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-15558"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22868"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30204"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47912"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58183"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58185"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58186"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58187"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58188"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58189"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61723"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61724"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61725"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61726"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61727"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61728"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61729"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61730"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61731"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61732"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-68119"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-68121"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25679"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25680"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27139"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27142"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27145"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33814"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33818"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39821"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39822"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39833"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39836"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42499"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42504"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42505"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42507"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42508"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46595"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46600"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56852"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56853"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56855"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56858"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56859"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56860"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56862"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56864"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56865"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78662"
}
],
"related": [],
"schema_version": "1.7.3",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"type": "CVSS_V3"
}
],
"summary": "Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection",
"upstream": [
"CVE-2025-15558",
"CVE-2025-22868",
"CVE-2025-30204",
"CVE-2025-47912",
"CVE-2025-58183",
"CVE-2025-58185",
"CVE-2025-58186",
"CVE-2025-58187",
"CVE-2025-58188",
"CVE-2025-58189",
"CVE-2025-61723",
"CVE-2025-61724",
"CVE-2025-61725",
"CVE-2025-61726",
"CVE-2025-61727",
"CVE-2025-61728",
"CVE-2025-61729",
"CVE-2025-61730",
"CVE-2025-61731",
"CVE-2025-61732",
"CVE-2025-68119",
"CVE-2025-68121",
"CVE-2026-25679",
"CVE-2026-25680",
"CVE-2026-27139",
"CVE-2026-27142",
"CVE-2026-27145",
"CVE-2026-33814",
"CVE-2026-33818",
"CVE-2026-39821",
"CVE-2026-39822",
"CVE-2026-39833",
"CVE-2026-39836",
"CVE-2026-42499",
"CVE-2026-42504",
"CVE-2026-42505",
"CVE-2026-42507",
"CVE-2026-42508",
"CVE-2026-46595",
"CVE-2026-46600",
"CVE-2026-56852",
"CVE-2026-56853",
"CVE-2026-56855",
"CVE-2026-56858",
"CVE-2026-56859",
"CVE-2026-56860",
"CVE-2026-56862",
"CVE-2026-56864",
"CVE-2026-56865",
"CVE-2026-78662",
"ghsa-259r-337f-4rfw",
"ghsa-6v2p-p543-phr9",
"ghsa-f6x5-jh6r-wrfv",
"ghsa-j5w8-q4qc-rx2x",
"ghsa-p436-gjf2-799p"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-CP63847 (CVE-2026-39821)
Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source websitePackage temporal-server version 1.28.4-r1 fixes 15 vulnerabilities: CVE-2026-39821, CVE-2026-33818, CVE-2026-46600, CVE-2026-56853, CVE-2026-56858...
| URL | Type | |
|---|---|---|
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "temporal-server"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.28.4-r1"
}
],
"type": "ECOSYSTEM"
}
],
"versions": [
"1.28.4-r1"
]
}
],
"credits": [],
"database_specific": {},
"details": "Package temporal-server version 1.28.4-r1 fixes 15 vulnerabilities: CVE-2026-39821, CVE-2026-33818, CVE-2026-46600, CVE-2026-56853, CVE-2026-56858...",
"id": "CLEANSTART-2026-CP63847",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-09-01T11:17:16Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/temporalio/temporal"
}
],
"related": [],
"schema_version": "1.7.3",
"summary": "Security fixes in temporal-server 1.28.4-r1",
"upstream": [
"CVE-2026-39821",
"CVE-2026-33818",
"CVE-2026-46600",
"CVE-2026-56853",
"CVE-2026-56858",
"CVE-2026-56859",
"CVE-2026-56860",
"CVE-2026-56862",
"CVE-2026-5724",
"CVE-2025-14987",
"CVE-2025-14986",
"CVE-2026-5199",
"ghsa-hrxh-6v49-42gf",
"ghsa-259r-337f-4rfw",
"CVE-2026-41178"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-CY42435 (CVE-2026-42508)
Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source websitePackage amazon-cloudwatch-agent version 1.300071.0-r1 fixes 36 vulnerabilities: CVE-2026-42508, CVE-2026-39835, CVE-2026-46598, CVE-2026-39828, CVE-2026-39829...
| URL | Type | |
|---|---|---|
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "amazon-cloudwatch-agent"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.300071.0-r1"
}
],
"type": "ECOSYSTEM"
}
],
"versions": [
"1.300071.0-r1"
]
}
],
"credits": [],
"database_specific": {},
"details": "Package amazon-cloudwatch-agent version 1.300071.0-r1 fixes 36 vulnerabilities: CVE-2026-42508, CVE-2026-39835, CVE-2026-46598, CVE-2026-39828, CVE-2026-39829...",
"id": "CLEANSTART-2026-CY42435",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-09-01T11:17:16Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/aws/amazon-cloudwatch-agent"
}
],
"related": [],
"schema_version": "1.7.3",
"summary": "Security fixes in amazon-cloudwatch-agent 1.300071.0-r1",
"upstream": [
"CVE-2026-42508",
"CVE-2026-39835",
"CVE-2026-46598",
"CVE-2026-39828",
"CVE-2026-39829",
"CVE-2026-46597",
"CVE-2026-39830",
"CVE-2026-39831",
"CVE-2026-39832",
"CVE-2026-39833",
"CVE-2026-39834",
"CVE-2026-46595",
"CVE-2026-39827",
"CVE-2026-33997",
"CVE-2026-41567",
"CVE-2026-42306",
"CVE-2026-34040",
"CVE-2026-41568",
"ghsa-hrxh-6v49-42gf",
"CVE-2026-46600",
"CVE-2026-25681",
"CVE-2026-27136",
"CVE-2026-39821",
"CVE-2026-42502",
"CVE-2026-42506",
"CVE-2026-25680",
"CVE-2026-42151",
"CVE-2026-44903",
"CVE-2026-40179",
"CVE-2026-56852",
"CVE-2026-39824",
"ghsa-xmrv-pmrh-hhx2",
"CVE-2026-2303",
"CVE-2026-41178",
"CVE-2026-42154",
"ghsa-259r-337f-4rfw"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-EC97009 (GHSA-HRXH-6V49-42GF)
Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source websitePackage argo-cd version 3.4.5-r2 fixes 3 vulnerabilities: ghsa-hrxh-6v49-42gf, ghsa-259r-337f-4rfw, CVE-2026-41178
| URL | Type | |
|---|---|---|
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "argo-cd"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "3.4.5-r2"
}
],
"type": "ECOSYSTEM"
}
],
"versions": [
"3.4.5-r2"
]
}
],
"credits": [],
"database_specific": {},
"details": "Package argo-cd version 3.4.5-r2 fixes 3 vulnerabilities: ghsa-hrxh-6v49-42gf, ghsa-259r-337f-4rfw, CVE-2026-41178",
"id": "CLEANSTART-2026-EC97009",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-09-01T11:17:16Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/argoproj/argo-cd"
}
],
"related": [],
"schema_version": "1.7.3",
"summary": "Security fixes in argo-cd 3.4.5-r2",
"upstream": [
"ghsa-hrxh-6v49-42gf",
"ghsa-259r-337f-4rfw",
"CVE-2026-41178"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-EK79845 (GHSA-259R-337F-4RFW)
Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source websitePackage ollama version 0.32.9-r1 fixes 1 vulnerabilities: ghsa-259r-337f-4rfw
| URL | Type | |
|---|---|---|
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "ollama"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.32.9-r1"
}
],
"type": "ECOSYSTEM"
}
],
"versions": [
"0.32.9-r1"
]
}
],
"credits": [],
"database_specific": {},
"details": "Package ollama version 0.32.9-r1 fixes 1 vulnerabilities: ghsa-259r-337f-4rfw",
"id": "CLEANSTART-2026-EK79845",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-09-01T11:17:16Z",
"references": [
{
"type": "WEB",
"url": "https://ollama.com"
}
],
"related": [],
"schema_version": "1.7.3",
"summary": "Security fixes in ollama 0.32.9-r1",
"upstream": [
"ghsa-259r-337f-4rfw"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-EM47790 (CVE-2025-15558)
Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source websitePackage tkn version 0.42.2-r1 fixes 57 vulnerabilities: CVE-2025-15558, CVE-2026-34040, CVE-2026-33997, CVE-2025-69725, CVE-2026-34986...
| URL | Type | |
|---|---|---|
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "tkn"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.42.2-r1"
}
],
"type": "ECOSYSTEM"
}
],
"versions": [
"0.42.2-r1"
]
}
],
"credits": [],
"database_specific": {},
"details": "Package tkn version 0.42.2-r1 fixes 57 vulnerabilities: CVE-2025-15558, CVE-2026-34040, CVE-2026-33997, CVE-2025-69725, CVE-2026-34986...",
"id": "CLEANSTART-2026-EM47790",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-09-01T11:17:16Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/tektoncd/cli"
}
],
"related": [],
"schema_version": "1.7.3",
"summary": "Security fixes in tkn 0.42.2-r1",
"upstream": [
"CVE-2025-15558",
"CVE-2026-34040",
"CVE-2026-33997",
"CVE-2025-69725",
"CVE-2026-34986",
"ghsa-gcjh-h69q-9w9g",
"CVE-2025-62375",
"ghsa-pmwq-pjrm-6p5r",
"CVE-2026-49478",
"CVE-2026-22772",
"CVE-2026-48702",
"CVE-2026-23831",
"CVE-2026-24117",
"CVE-2026-54787",
"CVE-2026-49834",
"CVE-2026-49835",
"CVE-2026-39984",
"CVE-2026-2303",
"CVE-2026-29181",
"CVE-2026-39883",
"CVE-2026-24051",
"CVE-2026-39828",
"CVE-2026-39829",
"CVE-2026-39830",
"CVE-2026-39831",
"CVE-2026-39832",
"CVE-2026-39835",
"CVE-2026-42508",
"CVE-2026-46595",
"CVE-2026-46597",
"CVE-2026-39827",
"CVE-2026-39833",
"CVE-2026-39834",
"CVE-2026-33818",
"CVE-2026-56853",
"CVE-2026-56858",
"CVE-2026-56859",
"CVE-2026-56860",
"CVE-2026-56862",
"CVE-2026-46598",
"CVE-2026-46600",
"CVE-2026-25681",
"CVE-2026-27136",
"CVE-2026-39821",
"CVE-2026-25680",
"CVE-2026-42502",
"CVE-2026-42506",
"CVE-2026-33814",
"CVE-2026-39824",
"CVE-2026-56852",
"ghsa-hrxh-6v49-42gf",
"CVE-2026-56864",
"CVE-2026-56865",
"ghsa-259r-337f-4rfw",
"ghsa-3fxj-6jh8-hvhx",
"ghsa-9g5q-2w5x-hmxf",
"ghsa-rjr7-jggh-pgcp"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-EP36304 (GHSA-259R-337F-4RFW)
Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source websitePackage ollama-fips version 0.32.1-r1 fixes 1 vulnerabilities: ghsa-259r-337f-4rfw
| URL | Type | |
|---|---|---|
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "ollama-fips"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.32.1-r1"
}
],
"type": "ECOSYSTEM"
}
],
"versions": [
"0.32.1-r1"
]
}
],
"credits": [],
"database_specific": {},
"details": "Package ollama-fips version 0.32.1-r1 fixes 1 vulnerabilities: ghsa-259r-337f-4rfw",
"id": "CLEANSTART-2026-EP36304",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-09-01T11:17:16Z",
"references": [
{
"type": "WEB",
"url": "https://ollama.com"
}
],
"related": [],
"schema_version": "1.7.3",
"summary": "Security fixes in ollama-fips 0.32.1-r1",
"upstream": [
"ghsa-259r-337f-4rfw"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-ER95870 (GHSA-259R-337F-4RFW)
Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source websitePackage tempo version 2.9.5-r2 fixes 1 vulnerabilities: ghsa-259r-337f-4rfw
| URL | Type | |
|---|---|---|
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "tempo"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "2.9.5-r2"
}
],
"type": "ECOSYSTEM"
}
],
"versions": [
"2.9.5-r2"
]
}
],
"credits": [],
"database_specific": {},
"details": "Package tempo version 2.9.5-r2 fixes 1 vulnerabilities: ghsa-259r-337f-4rfw",
"id": "CLEANSTART-2026-ER95870",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-09-01T11:17:16Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/grafana/tempo"
}
],
"related": [],
"schema_version": "1.7.3",
"summary": "Security fixes in tempo 2.9.5-r2",
"upstream": [
"ghsa-259r-337f-4rfw"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-ET14314 (GHSA-259R-337F-4RFW)
Vulnerability from cleanstart – Published: 2026-08-13 12:10 – Updated: 2026-09-18 11:59 – Source websitePackage cortex version 1.19.1-r2 fixes 2 vulnerabilities: ghsa-259r-337f-4rfw, CVE-2026-41178
| URL | Type | |
|---|---|---|
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "cortex"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.19.1-r2"
}
],
"type": "ECOSYSTEM"
}
],
"versions": [
"1.19.1-r2"
]
}
],
"credits": [],
"database_specific": {},
"details": "Package cortex version 1.19.1-r2 fixes 2 vulnerabilities: ghsa-259r-337f-4rfw, CVE-2026-41178",
"id": "CLEANSTART-2026-ET14314",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-08-13T12:10:09Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/cortexproject/cortex"
}
],
"related": [],
"schema_version": "1.7.3",
"summary": "Security fixes in cortex 1.19.1-r2",
"upstream": [
"ghsa-259r-337f-4rfw",
"CVE-2026-41178"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-FD87409 (CVE-2026-33818)
Vulnerability from cleanstart – Published: 2026-09-10 03:04 – Updated: 2026-09-18 11:59 – Source websiteMultiple security vulnerabilities affect the nats-streaming package. Previously, resolving relative paths containing parent directory ('. See references for individual vulnerability details.
| URL | Type | |||||||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "nats-streaming"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.24.6-r5"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"credits": [],
"database_specific": {},
"details": "Multiple security vulnerabilities affect the nats-streaming package. Previously, resolving relative paths containing parent directory (\u0027. See references for individual vulnerability details.",
"id": "CLEANSTART-2026-FD87409",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-09-10T03:04:43.115167Z",
"references": [
{
"type": "ADVISORY",
"url": "https://github.com/cleanstart-dev/cleanstart-security-advisories/tree/main/advisories/2026/CLEANSTART-2026-FD87409.json"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-33818"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39822"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42504"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42505"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-46600"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56853"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56858"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56860"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-259r-337f-4rfw"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33818"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39822"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42504"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42505"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46600"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56853"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56858"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56860"
}
],
"related": [],
"schema_version": "1.7.3",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"type": "CVSS_V3"
}
],
"summary": "Previously, resolving relative paths containing parent directory (\u0027",
"upstream": [
"CVE-2026-33818",
"CVE-2026-39822",
"CVE-2026-42504",
"CVE-2026-42505",
"CVE-2026-46600",
"CVE-2026-56853",
"CVE-2026-56858",
"CVE-2026-56860",
"ghsa-259r-337f-4rfw"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-FI83495 (GHSA-259R-337F-4RFW)
Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source websitePackage ollama version 0.32.0-r1 fixes 1 vulnerabilities: ghsa-259r-337f-4rfw
| URL | Type | |
|---|---|---|
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "ollama"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.32.0-r1"
}
],
"type": "ECOSYSTEM"
}
],
"versions": [
"0.32.0-r1"
]
}
],
"credits": [],
"database_specific": {},
"details": "Package ollama version 0.32.0-r1 fixes 1 vulnerabilities: ghsa-259r-337f-4rfw",
"id": "CLEANSTART-2026-FI83495",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-09-01T11:17:16Z",
"references": [
{
"type": "WEB",
"url": "https://ollama.com"
}
],
"related": [],
"schema_version": "1.7.3",
"summary": "Security fixes in ollama 0.32.0-r1",
"upstream": [
"ghsa-259r-337f-4rfw"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-FL45169 (GHSA-259R-337F-4RFW)
Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source websitePackage ollama-fips version 0.32.14-r2 fixes 1 vulnerabilities: ghsa-259r-337f-4rfw
| URL | Type | |
|---|---|---|
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "ollama-fips"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.32.14-r2"
}
],
"type": "ECOSYSTEM"
}
],
"versions": [
"0.32.14-r2"
]
}
],
"credits": [],
"database_specific": {},
"details": "Package ollama-fips version 0.32.14-r2 fixes 1 vulnerabilities: ghsa-259r-337f-4rfw",
"id": "CLEANSTART-2026-FL45169",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-09-01T11:17:16Z",
"references": [
{
"type": "WEB",
"url": "https://ollama.com"
}
],
"related": [],
"schema_version": "1.7.3",
"summary": "Security fixes in ollama-fips 0.32.14-r2",
"upstream": [
"ghsa-259r-337f-4rfw"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-FT20664 (CVE-2025-47912)
Vulnerability from cleanstart – Published: 2026-09-08 02:12 – Updated: 2026-09-18 11:59 – Source websiteMultiple security vulnerabilities affect the step package. gRPC-Go is the Go language implementation of gRPC. See references for individual vulnerability details.
| URL | Type | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "step"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.28.7-r6"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"credits": [],
"database_specific": {},
"details": "Multiple security vulnerabilities affect the step package. gRPC-Go is the Go language implementation of gRPC. See references for individual vulnerability details.",
"id": "CLEANSTART-2026-FT20664",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-09-08T02:12:53.280158Z",
"references": [
{
"type": "ADVISORY",
"url": "https://github.com/cleanstart-dev/cleanstart-security-advisories/tree/main/advisories/2026/CLEANSTART-2026-FT20664.json"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-47912"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-58183"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-58185"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-58186"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-58187"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-58188"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-58189"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-61723"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-61724"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-61725"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-62820"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-66406"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-25793"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-30836"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-33818"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39821"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39822"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-40097"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-41178"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42505"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-46600"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56852"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56853"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56855"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56858"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56859"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56860"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56862"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-78662"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-84304"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-259r-337f-4rfw"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-3fxj-6jh8-hvhx"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-9g5q-2w5x-hmxf"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-hrxh-6v49-42gf"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-rjr7-jggh-pgcp"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47912"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58183"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58185"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58186"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58187"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58188"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58189"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61723"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61724"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61725"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-62820"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-66406"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25793"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-30836"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33818"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39821"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39822"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-40097"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41178"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42505"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46600"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56852"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56853"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56855"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56858"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56859"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56860"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56862"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78662"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84304"
}
],
"related": [],
"schema_version": "1.7.3",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"type": "CVSS_V3"
}
],
"summary": "gRPC-Go is the Go language implementation of gRPC",
"upstream": [
"CVE-2025-47912",
"CVE-2025-58183",
"CVE-2025-58185",
"CVE-2025-58186",
"CVE-2025-58187",
"CVE-2025-58188",
"CVE-2025-58189",
"CVE-2025-61723",
"CVE-2025-61724",
"CVE-2025-61725",
"CVE-2025-62820",
"CVE-2025-66406",
"CVE-2026-25793",
"CVE-2026-30836",
"CVE-2026-33818",
"CVE-2026-39821",
"CVE-2026-39822",
"CVE-2026-40097",
"CVE-2026-41178",
"CVE-2026-42505",
"CVE-2026-46600",
"CVE-2026-56852",
"CVE-2026-56853",
"CVE-2026-56855",
"CVE-2026-56858",
"CVE-2026-56859",
"CVE-2026-56860",
"CVE-2026-56862",
"CVE-2026-78662",
"CVE-2026-84304",
"ghsa-259r-337f-4rfw",
"ghsa-3fxj-6jh8-hvhx",
"ghsa-9g5q-2w5x-hmxf",
"ghsa-hrxh-6v49-42gf",
"ghsa-rjr7-jggh-pgcp"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-FY98026 (GHSA-HRXH-6V49-42GF)
Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source websitePackage newrelic-infrastructure-agent version 1.76.2-r1 fixes 3 vulnerabilities: ghsa-hrxh-6v49-42gf, CVE-2026-41178, ghsa-259r-337f-4rfw
| URL | Type | |
|---|---|---|
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "newrelic-infrastructure-agent"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.76.2-r1"
}
],
"type": "ECOSYSTEM"
}
],
"versions": [
"1.76.2-r1"
]
}
],
"credits": [],
"database_specific": {},
"details": "Package newrelic-infrastructure-agent version 1.76.2-r1 fixes 3 vulnerabilities: ghsa-hrxh-6v49-42gf, CVE-2026-41178, ghsa-259r-337f-4rfw",
"id": "CLEANSTART-2026-FY98026",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-09-01T11:17:16Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/newrelic/infrastructure-agent"
}
],
"related": [],
"schema_version": "1.7.3",
"summary": "Security fixes in newrelic-infrastructure-agent 1.76.2-r1",
"upstream": [
"ghsa-hrxh-6v49-42gf",
"CVE-2026-41178",
"ghsa-259r-337f-4rfw"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-GB19497 (GHSA-259R-337F-4RFW)
Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source websitePackage ollama version 0.32.4-r1 fixes 1 vulnerabilities: ghsa-259r-337f-4rfw
| URL | Type | |
|---|---|---|
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "ollama"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.32.4-r1"
}
],
"type": "ECOSYSTEM"
}
],
"versions": [
"0.32.4-r1"
]
}
],
"credits": [],
"database_specific": {},
"details": "Package ollama version 0.32.4-r1 fixes 1 vulnerabilities: ghsa-259r-337f-4rfw",
"id": "CLEANSTART-2026-GB19497",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-09-01T11:17:16Z",
"references": [
{
"type": "WEB",
"url": "https://ollama.com"
}
],
"related": [],
"schema_version": "1.7.3",
"summary": "Security fixes in ollama 0.32.4-r1",
"upstream": [
"ghsa-259r-337f-4rfw"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-GJ00206 (CVE-2026-39822)
Vulnerability from cleanstart – Published: 2026-09-17 00:56 – Updated: 2026-09-18 11:59 – Source websiteMultiple security vulnerabilities affect the gitea package. Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. See references for individual vulnerability details.
| URL | Type | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "gitea"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.27.2-r2"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"credits": [],
"database_specific": {},
"details": "Multiple security vulnerabilities affect the gitea package. Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. See references for individual vulnerability details.",
"id": "CLEANSTART-2026-GJ00206",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-09-17T00:56:49.342966Z",
"references": [
{
"type": "ADVISORY",
"url": "https://github.com/cleanstart-dev/cleanstart-security-advisories/tree/main/advisories/2026/CLEANSTART-2026-GJ00206.json"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39822"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42505"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-46603"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56855"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56864"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56865"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-71556"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-71557"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-78662"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-84303"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-84304"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-84445"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-259r-337f-4rfw"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-3fxj-6jh8-hvhx"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-9g5q-2w5x-hmxf"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-hrxh-6v49-42gf"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-rjr7-jggh-pgcg"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39822"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42505"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46603"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56855"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56864"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56865"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-71556"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-71557"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78662"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84303"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84304"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84445"
}
],
"related": [],
"schema_version": "1.7.3",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"type": "CVSS_V3"
}
],
"summary": "Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection",
"upstream": [
"CVE-2026-39822",
"CVE-2026-42505",
"CVE-2026-46603",
"CVE-2026-56855",
"CVE-2026-56864",
"CVE-2026-56865",
"CVE-2026-71556",
"CVE-2026-71557",
"CVE-2026-78662",
"CVE-2026-84303",
"CVE-2026-84304",
"CVE-2026-84445",
"ghsa-259r-337f-4rfw",
"ghsa-3fxj-6jh8-hvhx",
"ghsa-9g5q-2w5x-hmxf",
"ghsa-hrxh-6v49-42gf",
"ghsa-rjr7-jggh-pgcg"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-GK68352 (CVE-2026-33818)
Vulnerability from cleanstart – Published: 2026-09-10 01:24 – Updated: 2026-09-18 11:59 – Source websiteMultiple security vulnerabilities affect the kubernetes-dns-node-cache package. The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. See references for individual vulnerability details.
| URL | Type | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "kubernetes-dns-node-cache"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.26.8-r7"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"credits": [],
"database_specific": {},
"details": "Multiple security vulnerabilities affect the kubernetes-dns-node-cache package. The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. See references for individual vulnerability details.",
"id": "CLEANSTART-2026-GK68352",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-09-10T01:24:08.392743Z",
"references": [
{
"type": "ADVISORY",
"url": "https://github.com/cleanstart-dev/cleanstart-security-advisories/tree/main/advisories/2026/CLEANSTART-2026-GK68352.json"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-33818"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39821"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39822"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42504"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42505"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-46600"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-50274"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56853"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56858"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56859"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56860"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56862"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56864"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56865"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-259r-337f-4rfw"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33818"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39821"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39822"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42504"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42505"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46600"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-50274"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56853"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56858"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56859"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56860"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56862"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56864"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56865"
}
],
"related": [],
"schema_version": "1.7.3",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"type": "CVSS_V3"
}
],
"summary": "ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label",
"upstream": [
"CVE-2026-33818",
"CVE-2026-39821",
"CVE-2026-39822",
"CVE-2026-42504",
"CVE-2026-42505",
"CVE-2026-46600",
"CVE-2026-50274",
"CVE-2026-56853",
"CVE-2026-56858",
"CVE-2026-56859",
"CVE-2026-56860",
"CVE-2026-56862",
"CVE-2026-56864",
"CVE-2026-56865",
"ghsa-259r-337f-4rfw"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-GO78201 (CVE-2026-33818)
Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source websitePackage tkn version 0.45.0-r1 fixes 42 vulnerabilities: CVE-2026-33818, CVE-2026-56853, CVE-2026-56858, CVE-2026-56859, CVE-2026-56860...
| URL | Type | |
|---|---|---|
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "tkn"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.45.0-r1"
}
],
"type": "ECOSYSTEM"
}
],
"versions": [
"0.45.0-r1"
]
}
],
"credits": [],
"database_specific": {},
"details": "Package tkn version 0.45.0-r1 fixes 42 vulnerabilities: CVE-2026-33818, CVE-2026-56853, CVE-2026-56858, CVE-2026-56859, CVE-2026-56860...",
"id": "CLEANSTART-2026-GO78201",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-09-01T11:17:16Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/tektoncd/cli"
}
],
"related": [],
"schema_version": "1.7.3",
"summary": "Security fixes in tkn 0.45.0-r1",
"upstream": [
"CVE-2026-33818",
"CVE-2026-56853",
"CVE-2026-56858",
"CVE-2026-56859",
"CVE-2026-56860",
"CVE-2026-56862",
"CVE-2026-34040",
"CVE-2026-33997",
"ghsa-gcjh-h69q-9w9g",
"CVE-2026-48702",
"CVE-2026-49834",
"CVE-2026-54787",
"CVE-2026-49835",
"CVE-2026-39828",
"CVE-2026-39829",
"CVE-2026-39830",
"CVE-2026-39831",
"CVE-2026-39832",
"CVE-2026-39835",
"CVE-2026-42508",
"CVE-2026-46595",
"CVE-2026-46597",
"CVE-2026-39827",
"CVE-2026-39833",
"CVE-2026-39834",
"CVE-2026-46598",
"CVE-2026-25681",
"CVE-2026-27136",
"CVE-2026-39821",
"CVE-2026-46600",
"CVE-2026-25680",
"CVE-2026-42502",
"CVE-2026-42506",
"CVE-2026-56852",
"ghsa-hrxh-6v49-42gf",
"CVE-2026-56864",
"CVE-2026-56865",
"ghsa-259r-337f-4rfw",
"ghsa-3fxj-6jh8-hvhx",
"ghsa-9g5q-2w5x-hmxf",
"ghsa-rjr7-jggh-pgcp",
"CVE-2026-41178"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-GP43617 (GHSA-259R-337F-4RFW)
Vulnerability from cleanstart – Published: 2026-08-13 12:10 – Updated: 2026-09-18 11:59 – Source websitePackage argo-workflows version 3.7.17-r2 fixes 1 vulnerabilities: ghsa-259r-337f-4rfw
| URL | Type | |
|---|---|---|
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "argo-workflows"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "3.7.17-r2"
}
],
"type": "ECOSYSTEM"
}
],
"versions": [
"3.7.17-r2"
]
}
],
"credits": [],
"database_specific": {},
"details": "Package argo-workflows version 3.7.17-r2 fixes 1 vulnerabilities: ghsa-259r-337f-4rfw",
"id": "CLEANSTART-2026-GP43617",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-08-13T12:10:09Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/argoproj/argo-workflows"
}
],
"related": [],
"schema_version": "1.7.3",
"summary": "Security fixes in argo-workflows 3.7.17-r2",
"upstream": [
"ghsa-259r-337f-4rfw"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-GQ91083 (CVE-2025-61732)
Vulnerability from cleanstart – Published: 2026-09-08 02:09 – Updated: 2026-09-18 11:59 – Source websiteMultiple security vulnerabilities affect the victoriametrics-operator-fips package. Previously, a channel registered in the mux's chanList is not usable until it is established. See references for individual vulnerability details.
| URL | Type | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "victoriametrics-operator-fips"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.71.0-r1"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"credits": [],
"database_specific": {},
"details": "Multiple security vulnerabilities affect the victoriametrics-operator-fips package. Previously, a channel registered in the mux\u0027s chanList is not usable until it is established. See references for individual vulnerability details.",
"id": "CLEANSTART-2026-GQ91083",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-09-08T02:09:21.753541Z",
"references": [
{
"type": "ADVISORY",
"url": "https://github.com/cleanstart-dev/cleanstart-security-advisories/tree/main/advisories/2026/CLEANSTART-2026-GQ91083.json"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-61732"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-68121"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-25679"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-27139"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-27142"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-33818"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39821"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39824"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-41178"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42504"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42506"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42507"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-46600"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56853"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56855"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56858"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56859"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56860"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56862"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-78662"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-259r-337f-4rfw"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-66jq-2c23-2xh5"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-9h8m-3fm2-qjrq"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-hrxh-6v49-42gf"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61732"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-68121"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25679"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27139"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27142"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33818"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39821"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39824"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41178"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42504"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42506"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42507"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46600"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56853"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56855"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56858"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56859"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56860"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56862"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78662"
}
],
"related": [],
"schema_version": "1.7.3",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"type": "CVSS_V3"
}
],
"summary": "Previously, a channel registered in the mux\u0027s chanList is not usable until it is established",
"upstream": [
"CVE-2025-61732",
"CVE-2025-68121",
"CVE-2026-25679",
"CVE-2026-27139",
"CVE-2026-27142",
"CVE-2026-33818",
"CVE-2026-39821",
"CVE-2026-39824",
"CVE-2026-41178",
"CVE-2026-42504",
"CVE-2026-42506",
"CVE-2026-42507",
"CVE-2026-46600",
"CVE-2026-56853",
"CVE-2026-56855",
"CVE-2026-56858",
"CVE-2026-56859",
"CVE-2026-56860",
"CVE-2026-56862",
"CVE-2026-78662",
"ghsa-259r-337f-4rfw",
"ghsa-66jq-2c23-2xh5",
"ghsa-9h8m-3fm2-qjrq",
"ghsa-hrxh-6v49-42gf"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-GR84261 (CVE-2026-33818)
Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source websitePackage tekton-chains-fips version 0.24.0-r1 fixes 26 vulnerabilities: CVE-2026-33818, CVE-2026-46600, CVE-2026-56853, CVE-2026-56858, CVE-2026-56859...
| URL | Type | |
|---|---|---|
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "tekton-chains-fips"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.24.0-r1"
}
],
"type": "ECOSYSTEM"
}
],
"versions": [
"0.24.0-r1"
]
}
],
"credits": [],
"database_specific": {},
"details": "Package tekton-chains-fips version 0.24.0-r1 fixes 26 vulnerabilities: CVE-2026-33818, CVE-2026-46600, CVE-2026-56853, CVE-2026-56858, CVE-2026-56859...",
"id": "CLEANSTART-2026-GR84261",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-09-01T11:17:16Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/tektoncd/chains"
}
],
"related": [],
"schema_version": "1.7.3",
"summary": "Security fixes in tekton-chains-fips 0.24.0-r1",
"upstream": [
"CVE-2026-33818",
"CVE-2026-46600",
"CVE-2026-56853",
"CVE-2026-56858",
"CVE-2026-56859",
"CVE-2026-56860",
"CVE-2026-56862",
"CVE-2026-39821",
"ghsa-gcjh-h69q-9w9g",
"ghsa-pmwq-pjrm-6p5r",
"CVE-2026-22703",
"CVE-2026-49478",
"CVE-2026-48702",
"CVE-2025-66564",
"CVE-2026-25542",
"CVE-2026-33022",
"CVE-2026-2303",
"CVE-2026-39883",
"ghsa-hrxh-6v49-42gf",
"CVE-2026-56864",
"CVE-2026-56865",
"ghsa-259r-337f-4rfw",
"ghsa-3fxj-6jh8-hvhx",
"ghsa-9g5q-2w5x-hmxf",
"ghsa-rjr7-jggh-pgcp",
"CVE-2026-41178"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-GU39170 (CVE-2026-42508)
Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source websitePackage amazon-cloudwatch-agent version 1.300070.0-r1 fixes 37 vulnerabilities: CVE-2026-42508, CVE-2026-39835, CVE-2026-46598, CVE-2026-39828, CVE-2026-39829...
| URL | Type | |
|---|---|---|
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "amazon-cloudwatch-agent"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.300070.0-r1"
}
],
"type": "ECOSYSTEM"
}
],
"versions": [
"1.300070.0-r1"
]
}
],
"credits": [],
"database_specific": {},
"details": "Package amazon-cloudwatch-agent version 1.300070.0-r1 fixes 37 vulnerabilities: CVE-2026-42508, CVE-2026-39835, CVE-2026-46598, CVE-2026-39828, CVE-2026-39829...",
"id": "CLEANSTART-2026-GU39170",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-09-01T11:17:16Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/aws/amazon-cloudwatch-agent"
}
],
"related": [],
"schema_version": "1.7.3",
"summary": "Security fixes in amazon-cloudwatch-agent 1.300070.0-r1",
"upstream": [
"CVE-2026-42508",
"CVE-2026-39835",
"CVE-2026-46598",
"CVE-2026-39828",
"CVE-2026-39829",
"CVE-2026-46597",
"CVE-2026-39830",
"CVE-2026-39831",
"CVE-2026-39832",
"CVE-2026-39833",
"CVE-2026-39834",
"CVE-2026-46595",
"CVE-2026-39827",
"CVE-2026-33997",
"CVE-2026-41567",
"CVE-2026-42306",
"CVE-2026-34040",
"CVE-2026-41568",
"ghsa-hrxh-6v49-42gf",
"CVE-2025-63811",
"CVE-2026-25681",
"CVE-2026-27136",
"CVE-2026-39821",
"CVE-2026-42502",
"CVE-2026-42506",
"CVE-2026-25680",
"CVE-2026-46600",
"CVE-2026-42151",
"CVE-2026-44903",
"CVE-2026-42154",
"CVE-2026-56852",
"ghsa-xmrv-pmrh-hhx2",
"CVE-2026-26958",
"CVE-2026-2303",
"CVE-2026-41178",
"CVE-2026-39824",
"ghsa-259r-337f-4rfw"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-GV17876 (CVE-2026-25680)
Vulnerability from cleanstart – Published: 2026-09-08 00:56 – Updated: 2026-09-18 11:59 – Source websiteMultiple security vulnerabilities affect the rancher-fleet-agent package. Helm is a package manager for Charts for Kubernetes. See references for individual vulnerability details.
| URL | Type | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "rancher-fleet-agent"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.15.6-r0"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"credits": [],
"database_specific": {},
"details": "Multiple security vulnerabilities affect the rancher-fleet-agent package. Helm is a package manager for Charts for Kubernetes. See references for individual vulnerability details.",
"id": "CLEANSTART-2026-GV17876",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-09-08T00:56:47.503504Z",
"references": [
{
"type": "ADVISORY",
"url": "https://github.com/cleanstart-dev/cleanstart-security-advisories/tree/main/advisories/2026/CLEANSTART-2026-GV17876.json"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-25680"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-25681"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-27136"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-29181"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-33186"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-33814"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-35206"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-35469"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39821"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39824"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39827"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39828"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39829"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39830"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39831"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39832"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39833"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39834"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39835"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42502"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42506"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42508"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-46595"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-46597"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-46598"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-46600"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-46680"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-47262"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-48978"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-50151"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-50162"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-50163"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-50195"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-53488"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-53489"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-53492"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56852"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56854"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-84304"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-259r-337f-4rfw"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-hrxh-6v49-42gf"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-vh4v-2xq2-g5cg"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25680"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25681"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27136"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-29181"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33186"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33814"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-35206"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-35469"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39821"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39824"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39827"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39828"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39829"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39830"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39831"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39832"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39833"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39834"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39835"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42502"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42506"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42508"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46595"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46597"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46598"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46600"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46680"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-47262"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-48978"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-50151"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-50162"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-50163"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-50195"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-53488"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-53489"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-53492"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56852"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56854"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84304"
}
],
"related": [],
"schema_version": "1.7.3",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"type": "CVSS_V3"
}
],
"summary": "Helm is a package manager for Charts for Kubernetes",
"upstream": [
"CVE-2026-25680",
"CVE-2026-25681",
"CVE-2026-27136",
"CVE-2026-29181",
"CVE-2026-33186",
"CVE-2026-33814",
"CVE-2026-35206",
"CVE-2026-35469",
"CVE-2026-39821",
"CVE-2026-39824",
"CVE-2026-39827",
"CVE-2026-39828",
"CVE-2026-39829",
"CVE-2026-39830",
"CVE-2026-39831",
"CVE-2026-39832",
"CVE-2026-39833",
"CVE-2026-39834",
"CVE-2026-39835",
"CVE-2026-42502",
"CVE-2026-42506",
"CVE-2026-42508",
"CVE-2026-46595",
"CVE-2026-46597",
"CVE-2026-46598",
"CVE-2026-46600",
"CVE-2026-46680",
"CVE-2026-47262",
"CVE-2026-48978",
"CVE-2026-50151",
"CVE-2026-50162",
"CVE-2026-50163",
"CVE-2026-50195",
"CVE-2026-53488",
"CVE-2026-53489",
"CVE-2026-53492",
"CVE-2026-56852",
"CVE-2026-56854",
"CVE-2026-84304",
"ghsa-259r-337f-4rfw",
"ghsa-hrxh-6v49-42gf",
"ghsa-vh4v-2xq2-g5cg"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-HA54107 (GHSA-GCJH-H69Q-9W9G)
Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source websitePackage tekton-chains version 0.25.2-r1 fixes 23 vulnerabilities: ghsa-gcjh-h69q-9w9g, ghsa-pmwq-pjrm-6p5r, CVE-2026-49478, CVE-2026-48702, CVE-2026-49834...
| URL | Type | |
|---|---|---|
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "tekton-chains"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.25.2-r1"
}
],
"type": "ECOSYSTEM"
}
],
"versions": [
"0.25.2-r1"
]
}
],
"credits": [],
"database_specific": {},
"details": "Package tekton-chains version 0.25.2-r1 fixes 23 vulnerabilities: ghsa-gcjh-h69q-9w9g, ghsa-pmwq-pjrm-6p5r, CVE-2026-49478, CVE-2026-48702, CVE-2026-49834...",
"id": "CLEANSTART-2026-HA54107",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-09-01T11:17:16Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/tektoncd/chains"
}
],
"related": [],
"schema_version": "1.7.3",
"summary": "Security fixes in tekton-chains 0.25.2-r1",
"upstream": [
"ghsa-gcjh-h69q-9w9g",
"ghsa-pmwq-pjrm-6p5r",
"CVE-2026-49478",
"CVE-2026-48702",
"CVE-2026-49834",
"CVE-2026-54787",
"CVE-2026-39984",
"CVE-2026-49835",
"CVE-2026-40161",
"CVE-2026-40938",
"CVE-2026-25542",
"CVE-2026-40923",
"CVE-2026-40924",
"CVE-2026-2303",
"CVE-2026-39883",
"ghsa-hrxh-6v49-42gf",
"CVE-2026-56864",
"CVE-2026-56865",
"ghsa-259r-337f-4rfw",
"ghsa-3fxj-6jh8-hvhx",
"ghsa-9g5q-2w5x-hmxf",
"ghsa-rjr7-jggh-pgcp",
"CVE-2026-41178"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-HB08666 (CVE-2026-39821)
Vulnerability from cleanstart – Published: 2026-09-08 01:57 – Updated: 2026-09-18 11:59 – Source websiteMultiple security vulnerabilities affect the dynatrace-operator package. The source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for CVE-2026-46595. See references for individual vulnerability details.
| URL | Type | |||||||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "dynatrace-operator"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.9.0-r4"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"credits": [],
"database_specific": {},
"details": "Multiple security vulnerabilities affect the dynatrace-operator package. The source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for CVE-2026-46595. See references for individual vulnerability details.",
"id": "CLEANSTART-2026-HB08666",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-09-08T01:57:20.508164Z",
"references": [
{
"type": "ADVISORY",
"url": "https://github.com/cleanstart-dev/cleanstart-security-advisories/tree/main/advisories/2026/CLEANSTART-2026-HB08666.json"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39821"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-41178"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-46600"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56854"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56859"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56860"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56864"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-84304"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-259r-337f-4rfw"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39821"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41178"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46600"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56854"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56859"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56860"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56864"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84304"
}
],
"related": [],
"schema_version": "1.7.3",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"type": "CVSS_V3"
}
],
"summary": "source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for CVE-2...",
"upstream": [
"CVE-2026-39821",
"CVE-2026-41178",
"CVE-2026-46600",
"CVE-2026-56854",
"CVE-2026-56859",
"CVE-2026-56860",
"CVE-2026-56864",
"CVE-2026-84304",
"ghsa-259r-337f-4rfw"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-HO97876 (CVE-2026-39821)
Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source websitePackage temporal-server version 1.30.5-r1 fixes 14 vulnerabilities: CVE-2026-39821, CVE-2026-33818, CVE-2026-46600, CVE-2026-56853, CVE-2026-56858...
| URL | Type | |
|---|---|---|
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "temporal-server"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.30.5-r1"
}
],
"type": "ECOSYSTEM"
}
],
"versions": [
"1.30.5-r1"
]
}
],
"credits": [],
"database_specific": {},
"details": "Package temporal-server version 1.30.5-r1 fixes 14 vulnerabilities: CVE-2026-39821, CVE-2026-33818, CVE-2026-46600, CVE-2026-56853, CVE-2026-56858...",
"id": "CLEANSTART-2026-HO97876",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-09-01T11:17:16Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/temporalio/temporal"
}
],
"related": [],
"schema_version": "1.7.3",
"summary": "Security fixes in temporal-server 1.30.5-r1",
"upstream": [
"CVE-2026-39821",
"CVE-2026-33818",
"CVE-2026-46600",
"CVE-2026-56853",
"CVE-2026-56858",
"CVE-2026-56859",
"CVE-2026-56860",
"CVE-2026-56862",
"CVE-2026-5724",
"CVE-2025-14987",
"CVE-2025-14986",
"CVE-2026-5199",
"ghsa-hrxh-6v49-42gf",
"ghsa-259r-337f-4rfw"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-HR50080 (CVE-2026-24051)
Vulnerability from cleanstart – Published: 2026-09-10 02:09 – Updated: 2026-09-18 11:59 – Source websiteMultiple security vulnerabilities affect the cert-manager package. The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. See references for individual vulnerability details.
| URL | Type | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "cert-manager"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.19.2-r0"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"credits": [],
"database_specific": {},
"details": "Multiple security vulnerabilities affect the cert-manager package. The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. See references for individual vulnerability details.",
"id": "CLEANSTART-2026-HR50080",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-09-10T02:09:11.315492Z",
"references": [
{
"type": "ADVISORY",
"url": "https://github.com/cleanstart-dev/cleanstart-security-advisories/tree/main/advisories/2026/CLEANSTART-2026-HR50080.json"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-24051"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-25680"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-25681"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-27136"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-27145"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-32952"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-33186"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-33811"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-33814"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-33818"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-34986"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39820"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39821"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39822"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39823"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39824"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39825"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39826"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39827"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39828"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39829"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39830"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39831"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39832"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39833"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39834"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39835"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39836"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39883"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-41178"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42499"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42502"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42504"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42505"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42506"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42507"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42508"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-46595"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-46597"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-46598"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-46600"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56852"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56853"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56858"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56859"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56860"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56862"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-73500"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-259r-337f-4rfw"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-78h2-9frx-2jm8"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-9h8m-3fm2-qjrq"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-gcjh-h69q-9w9g"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-hrxh-6v49-42gf"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-p77j-4mvh-x3m3"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-24051"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25680"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25681"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27136"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27145"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32952"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33186"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33811"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33814"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33818"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-34986"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39820"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39821"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39822"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39823"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39824"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39825"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39826"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39827"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39828"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39829"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39830"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39831"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39832"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39833"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39834"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39835"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39836"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39883"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41178"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42499"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42502"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42504"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42505"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42506"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42507"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42508"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46595"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46597"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46598"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46600"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56852"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56853"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56858"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56859"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56860"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56862"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-73500"
}
],
"related": [],
"schema_version": "1.7.3",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"type": "CVSS_V3"
}
],
"summary": "ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label",
"upstream": [
"CVE-2026-24051",
"CVE-2026-25680",
"CVE-2026-25681",
"CVE-2026-27136",
"CVE-2026-27145",
"CVE-2026-32952",
"CVE-2026-33186",
"CVE-2026-33811",
"CVE-2026-33814",
"CVE-2026-33818",
"CVE-2026-34986",
"CVE-2026-39820",
"CVE-2026-39821",
"CVE-2026-39822",
"CVE-2026-39823",
"CVE-2026-39824",
"CVE-2026-39825",
"CVE-2026-39826",
"CVE-2026-39827",
"CVE-2026-39828",
"CVE-2026-39829",
"CVE-2026-39830",
"CVE-2026-39831",
"CVE-2026-39832",
"CVE-2026-39833",
"CVE-2026-39834",
"CVE-2026-39835",
"CVE-2026-39836",
"CVE-2026-39883",
"CVE-2026-41178",
"CVE-2026-42499",
"CVE-2026-42502",
"CVE-2026-42504",
"CVE-2026-42505",
"CVE-2026-42506",
"CVE-2026-42507",
"CVE-2026-42508",
"CVE-2026-46595",
"CVE-2026-46597",
"CVE-2026-46598",
"CVE-2026-46600",
"CVE-2026-56852",
"CVE-2026-56853",
"CVE-2026-56858",
"CVE-2026-56859",
"CVE-2026-56860",
"CVE-2026-56862",
"CVE-2026-73500",
"ghsa-259r-337f-4rfw",
"ghsa-78h2-9frx-2jm8",
"ghsa-9h8m-3fm2-qjrq",
"ghsa-gcjh-h69q-9w9g",
"ghsa-hrxh-6v49-42gf",
"ghsa-p77j-4mvh-x3m3"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-IB62904 (CVE-2026-39821)
Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source websitePackage temporal-server version 1.28.4-r2 fixes 15 vulnerabilities: CVE-2026-39821, CVE-2026-33818, CVE-2026-46600, CVE-2026-56853, CVE-2026-56858...
| URL | Type | |
|---|---|---|
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "temporal-server"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.28.4-r2"
}
],
"type": "ECOSYSTEM"
}
],
"versions": [
"1.28.4-r2"
]
}
],
"credits": [],
"database_specific": {},
"details": "Package temporal-server version 1.28.4-r2 fixes 15 vulnerabilities: CVE-2026-39821, CVE-2026-33818, CVE-2026-46600, CVE-2026-56853, CVE-2026-56858...",
"id": "CLEANSTART-2026-IB62904",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-09-01T11:17:16Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/temporalio/temporal"
}
],
"related": [],
"schema_version": "1.7.3",
"summary": "Security fixes in temporal-server 1.28.4-r2",
"upstream": [
"CVE-2026-39821",
"CVE-2026-33818",
"CVE-2026-46600",
"CVE-2026-56853",
"CVE-2026-56858",
"CVE-2026-56859",
"CVE-2026-56860",
"CVE-2026-56862",
"CVE-2026-5724",
"CVE-2025-14987",
"CVE-2025-14986",
"CVE-2026-5199",
"ghsa-hrxh-6v49-42gf",
"ghsa-259r-337f-4rfw",
"CVE-2026-41178"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-IK56508 (CVE-2026-25680)
Vulnerability from cleanstart – Published: 2026-09-16 01:01 – Updated: 2026-09-18 11:59 – Source websiteMultiple security vulnerabilities affect the cadvisor package. Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. See references for individual vulnerability details.
| URL | Type | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "cadvisor"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.60.5-r2"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"credits": [],
"database_specific": {},
"details": "Multiple security vulnerabilities affect the cadvisor package. Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. See references for individual vulnerability details.",
"id": "CLEANSTART-2026-IK56508",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-09-16T01:01:14.670585Z",
"references": [
{
"type": "ADVISORY",
"url": "https://github.com/cleanstart-dev/cleanstart-security-advisories/tree/main/advisories/2026/CLEANSTART-2026-IK56508.json"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-25680"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-25681"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-27136"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-27145"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-29181"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-33186"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-33818"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39821"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39824"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39827"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39828"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39829"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39830"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39831"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39832"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39833"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39834"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39835"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-41579"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42502"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42504"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42506"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42507"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42508"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-46595"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-46597"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-46598"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-46600"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56853"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56855"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56858"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56859"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56860"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56862"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-78662"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-84303"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-84304"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-84445"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-259r-337f-4rfw"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-hrxh-6v49-42gf"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-mh2q-q3fh-2475"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-xjvp-4fhw-gc47"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25680"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25681"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27136"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27145"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-29181"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33186"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33818"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39821"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39824"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39827"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39828"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39829"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39830"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39831"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39832"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39833"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39834"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39835"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41579"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42502"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42504"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42506"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42507"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42508"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46595"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46597"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46598"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46600"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56853"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56855"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56858"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56859"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56860"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56862"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78662"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84303"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84304"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84445"
}
],
"related": [],
"schema_version": "1.7.3",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"type": "CVSS_V3"
}
],
"summary": "Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection",
"upstream": [
"CVE-2026-25680",
"CVE-2026-25681",
"CVE-2026-27136",
"CVE-2026-27145",
"CVE-2026-29181",
"CVE-2026-33186",
"CVE-2026-33818",
"CVE-2026-39821",
"CVE-2026-39824",
"CVE-2026-39827",
"CVE-2026-39828",
"CVE-2026-39829",
"CVE-2026-39830",
"CVE-2026-39831",
"CVE-2026-39832",
"CVE-2026-39833",
"CVE-2026-39834",
"CVE-2026-39835",
"CVE-2026-41579",
"CVE-2026-42502",
"CVE-2026-42504",
"CVE-2026-42506",
"CVE-2026-42507",
"CVE-2026-42508",
"CVE-2026-46595",
"CVE-2026-46597",
"CVE-2026-46598",
"CVE-2026-46600",
"CVE-2026-56853",
"CVE-2026-56855",
"CVE-2026-56858",
"CVE-2026-56859",
"CVE-2026-56860",
"CVE-2026-56862",
"CVE-2026-78662",
"CVE-2026-84303",
"CVE-2026-84304",
"CVE-2026-84445",
"ghsa-259r-337f-4rfw",
"ghsa-hrxh-6v49-42gf",
"ghsa-mh2q-q3fh-2475",
"ghsa-xjvp-4fhw-gc47"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-IS78554 (GHSA-259R-337F-4RFW)
Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source websitePackage ollama-fips version 0.32.7-r1 fixes 1 vulnerabilities: ghsa-259r-337f-4rfw
| URL | Type | |
|---|---|---|
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "ollama-fips"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.32.7-r1"
}
],
"type": "ECOSYSTEM"
}
],
"versions": [
"0.32.7-r1"
]
}
],
"credits": [],
"database_specific": {},
"details": "Package ollama-fips version 0.32.7-r1 fixes 1 vulnerabilities: ghsa-259r-337f-4rfw",
"id": "CLEANSTART-2026-IS78554",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-09-01T11:17:16Z",
"references": [
{
"type": "WEB",
"url": "https://ollama.com"
}
],
"related": [],
"schema_version": "1.7.3",
"summary": "Security fixes in ollama-fips 0.32.7-r1",
"upstream": [
"ghsa-259r-337f-4rfw"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-IW23752 (CVE-2026-56852)
Vulnerability from cleanstart – Published: 2026-08-13 12:10 – Updated: 2026-09-18 11:59 – Source websitePackage weaviate-fips version 1.38.6-r1 fixes 3 vulnerabilities: CVE-2026-56852, CVE-2026-46600, ghsa-259r-337f-4rfw
| URL | Type | |
|---|---|---|
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "weaviate-fips"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.38.6-r1"
}
],
"type": "ECOSYSTEM"
}
],
"versions": [
"1.38.6-r1"
]
}
],
"credits": [],
"database_specific": {},
"details": "Package weaviate-fips version 1.38.6-r1 fixes 3 vulnerabilities: CVE-2026-56852, CVE-2026-46600, ghsa-259r-337f-4rfw",
"id": "CLEANSTART-2026-IW23752",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-08-13T12:10:09Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/weaviate/weaviate"
}
],
"related": [],
"schema_version": "1.7.3",
"summary": "Security fixes in weaviate-fips 1.38.6-r1",
"upstream": [
"CVE-2026-56852",
"CVE-2026-46600",
"ghsa-259r-337f-4rfw"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-JC77975 (CVE-2026-46600)
Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source websitePackage tempo version 2.10.8-r1 fixes 2 vulnerabilities: CVE-2026-46600, ghsa-259r-337f-4rfw
| URL | Type | |
|---|---|---|
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "tempo"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "2.10.8-r1"
}
],
"type": "ECOSYSTEM"
}
],
"versions": [
"2.10.8-r1"
]
}
],
"credits": [],
"database_specific": {},
"details": "Package tempo version 2.10.8-r1 fixes 2 vulnerabilities: CVE-2026-46600, ghsa-259r-337f-4rfw",
"id": "CLEANSTART-2026-JC77975",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-09-01T11:17:16Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/grafana/tempo"
}
],
"related": [],
"schema_version": "1.7.3",
"summary": "Security fixes in tempo 2.10.8-r1",
"upstream": [
"CVE-2026-46600",
"ghsa-259r-337f-4rfw"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-JD10612 (CVE-2026-2303)
Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source websitePackage karma version 0.130-r1 fixes 6 vulnerabilities: CVE-2026-2303, CVE-2026-39824, ghsa-259r-337f-4rfw, ghsa-3fxj-6jh8-hvhx, ghsa-9g5q-2w5x-hmxf...
| URL | Type | |
|---|---|---|
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "karma"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.130-r1"
}
],
"type": "ECOSYSTEM"
}
],
"versions": [
"0.130-r1"
]
}
],
"credits": [],
"database_specific": {},
"details": "Package karma version 0.130-r1 fixes 6 vulnerabilities: CVE-2026-2303, CVE-2026-39824, ghsa-259r-337f-4rfw, ghsa-3fxj-6jh8-hvhx, ghsa-9g5q-2w5x-hmxf...",
"id": "CLEANSTART-2026-JD10612",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-09-01T11:17:16Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/prymitive/karma.git"
}
],
"related": [],
"schema_version": "1.7.3",
"summary": "Security fixes in karma 0.130-r1",
"upstream": [
"CVE-2026-2303",
"CVE-2026-39824",
"ghsa-259r-337f-4rfw",
"ghsa-3fxj-6jh8-hvhx",
"ghsa-9g5q-2w5x-hmxf",
"ghsa-rjr7-jggh-pgcp"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-JM50700 (GHSA-259R-337F-4RFW)
Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source websitePackage ollama-fips version 0.32.4-r1 fixes 1 vulnerabilities: ghsa-259r-337f-4rfw
| URL | Type | |
|---|---|---|
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "ollama-fips"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.32.4-r1"
}
],
"type": "ECOSYSTEM"
}
],
"versions": [
"0.32.4-r1"
]
}
],
"credits": [],
"database_specific": {},
"details": "Package ollama-fips version 0.32.4-r1 fixes 1 vulnerabilities: ghsa-259r-337f-4rfw",
"id": "CLEANSTART-2026-JM50700",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-09-01T11:17:16Z",
"references": [
{
"type": "WEB",
"url": "https://ollama.com"
}
],
"related": [],
"schema_version": "1.7.3",
"summary": "Security fixes in ollama-fips 0.32.4-r1",
"upstream": [
"ghsa-259r-337f-4rfw"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-JX39152 (CVE-2026-49834)
Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source websitePackage spire-server version 1.14.7-r0 fixes 16 vulnerabilities: CVE-2026-49834, CVE-2026-24122, CVE-2026-39395, CVE-2026-41178, CVE-2026-41568...
| URL | Type | |
|---|---|---|
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "spire-server"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.14.7-r0"
}
],
"type": "ECOSYSTEM"
}
],
"versions": [
"1.14.7-r0"
]
}
],
"credits": [],
"database_specific": {},
"details": "Package spire-server version 1.14.7-r0 fixes 16 vulnerabilities: CVE-2026-49834, CVE-2026-24122, CVE-2026-39395, CVE-2026-41178, CVE-2026-41568...",
"id": "CLEANSTART-2026-JX39152",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-09-01T11:17:16Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/spiffe/spire"
}
],
"related": [],
"schema_version": "1.7.3",
"summary": "Security fixes in spire-server 1.14.7-r0",
"upstream": [
"CVE-2026-49834",
"CVE-2026-24122",
"CVE-2026-39395",
"CVE-2026-41178",
"CVE-2026-41568",
"CVE-2026-41889",
"CVE-2026-48702",
"CVE-2026-49834",
"CVE-2026-49835",
"CVE-2026-54787",
"CVE-2026-56864",
"CVE-2026-56865",
"ghsa-259r-337f-4rfw",
"ghsa-3fxj-6jh8-hvhx",
"ghsa-9g5q-2w5x-hmxf",
"ghsa-rjr7-jggh-pgcp"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-KI63132 (GHSA-HRXH-6V49-42GF)
Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source websitePackage prometheus-fips version 3.12.0-r1 fixes 2 vulnerabilities: ghsa-hrxh-6v49-42gf, ghsa-259r-337f-4rfw
| URL | Type | |
|---|---|---|
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "prometheus-fips"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "3.12.0-r1"
}
],
"type": "ECOSYSTEM"
}
],
"versions": [
"3.12.0-r1"
]
}
],
"credits": [],
"database_specific": {},
"details": "Package prometheus-fips version 3.12.0-r1 fixes 2 vulnerabilities: ghsa-hrxh-6v49-42gf, ghsa-259r-337f-4rfw",
"id": "CLEANSTART-2026-KI63132",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-09-01T11:17:16Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/prometheus/prometheus"
}
],
"related": [],
"schema_version": "1.7.3",
"summary": "Security fixes in prometheus-fips 3.12.0-r1",
"upstream": [
"ghsa-hrxh-6v49-42gf",
"ghsa-259r-337f-4rfw"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-KP10631 (CVE-2025-22868)
Vulnerability from cleanstart – Published: 2026-09-10 00:42 – Updated: 2026-09-18 11:59 – Source websiteMultiple security vulnerabilities affect the vault-k8s package. The source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for CVE-2026-46595. See references for individual vulnerability details.
| URL | Type | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "vault-k8s"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.5.0.r4"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"credits": [],
"database_specific": {},
"details": "Multiple security vulnerabilities affect the vault-k8s package. The source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for CVE-2026-46595. See references for individual vulnerability details.",
"id": "CLEANSTART-2026-KP10631",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-09-10T00:42:34.310130Z",
"references": [
{
"type": "ADVISORY",
"url": "https://github.com/cleanstart-dev/cleanstart-security-advisories/tree/main/advisories/2026/CLEANSTART-2026-KP10631.json"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-22868"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-33818"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39821"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-46600"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56853"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56854"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56858"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56859"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56860"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56862"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-259r-337f-4rfw"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-6v2p-p543-phr9"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22868"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33818"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39821"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46600"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56853"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56854"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56858"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56859"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56860"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56862"
}
],
"related": [],
"schema_version": "1.7.3",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"type": "CVSS_V3"
}
],
"summary": "source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for CVE-2...",
"upstream": [
"CVE-2025-22868",
"CVE-2026-33818",
"CVE-2026-39821",
"CVE-2026-46600",
"CVE-2026-56853",
"CVE-2026-56854",
"CVE-2026-56858",
"CVE-2026-56859",
"CVE-2026-56860",
"CVE-2026-56862",
"ghsa-259r-337f-4rfw",
"ghsa-6v2p-p543-phr9"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-KP99907 (CVE-2026-56864)
Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source websitePackage crossplane version 2.3.4-r2 fixes 4 vulnerabilities: CVE-2026-56864, CVE-2026-56865, ghsa-259r-337f-4rfw, CVE-2026-54787
| URL | Type | |
|---|---|---|
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "crossplane"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "2.3.4-r2"
}
],
"type": "ECOSYSTEM"
}
],
"versions": [
"2.3.4-r2"
]
}
],
"credits": [],
"database_specific": {},
"details": "Package crossplane version 2.3.4-r2 fixes 4 vulnerabilities: CVE-2026-56864, CVE-2026-56865, ghsa-259r-337f-4rfw, CVE-2026-54787",
"id": "CLEANSTART-2026-KP99907",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-09-01T11:17:16Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/crossplane/crossplane"
}
],
"related": [],
"schema_version": "1.7.3",
"summary": "Security fixes in crossplane 2.3.4-r2",
"upstream": [
"CVE-2026-56864",
"CVE-2026-56865",
"ghsa-259r-337f-4rfw",
"CVE-2026-54787"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-KQ21500 (GHSA-R277-6W6Q-XMQW)
Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source websitePackage grafana version 12.3.10-r1 fixes 15 vulnerabilities: ghsa-r277-6w6q-xmqw, ghsa-jpcw-4wr7-c3vq, ghsa-gcjh-h69q-9w9g, CVE-2026-21728, CVE-2026-28377...
| URL | Type | |
|---|---|---|
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "grafana"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "12.3.10-r1"
}
],
"type": "ECOSYSTEM"
}
],
"versions": [
"12.3.10-r1"
]
}
],
"credits": [],
"database_specific": {},
"details": "Package grafana version 12.3.10-r1 fixes 15 vulnerabilities: ghsa-r277-6w6q-xmqw, ghsa-jpcw-4wr7-c3vq, ghsa-gcjh-h69q-9w9g, CVE-2026-21728, CVE-2026-28377...",
"id": "CLEANSTART-2026-KQ21500",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-09-01T11:17:16Z",
"references": [
{
"type": "WEB",
"url": "https://grafana.com"
}
],
"related": [],
"schema_version": "1.7.3",
"summary": "Security fixes in grafana 12.3.10-r1",
"upstream": [
"ghsa-r277-6w6q-xmqw",
"ghsa-jpcw-4wr7-c3vq",
"ghsa-gcjh-h69q-9w9g",
"CVE-2026-21728",
"CVE-2026-28377",
"CVE-2026-48096",
"CVE-2026-55689",
"CVE-2026-55170",
"CVE-2026-42151",
"CVE-2026-44903",
"CVE-2026-40179",
"CVE-2026-2303",
"CVE-2026-39882",
"ghsa-259r-337f-4rfw",
"CVE-2026-41178"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-KQ31223 (CVE-2026-2303)
Vulnerability from cleanstart – Published: 2026-09-18 01:30 – Updated: 2026-09-18 11:59 – Source websiteMultiple security vulnerabilities affect the vault package. gRPC-Go is the Go language implementation of gRPC. See references for individual vulnerability details.
| URL | Type | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "vault"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.21.4-r9"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"credits": [],
"database_specific": {},
"details": "Multiple security vulnerabilities affect the vault package. gRPC-Go is the Go language implementation of gRPC. See references for individual vulnerability details.",
"id": "CLEANSTART-2026-KQ31223",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-09-18T01:30:00.429155Z",
"references": [
{
"type": "ADVISORY",
"url": "https://github.com/cleanstart-dev/cleanstart-security-advisories/tree/main/advisories/2026/CLEANSTART-2026-KQ31223.json"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-2303"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-25680"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-25681"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-27136"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-27145"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-32280"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-32281"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-32282"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-32283"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-32288"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-32289"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-32952"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-33186"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-33810"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-33811"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-33814"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-33816"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-33818"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-34040"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-34986"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39817"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39819"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39820"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39821"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39822"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39823"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39824"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39825"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39826"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39827"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39828"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39829"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39830"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39831"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39832"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39833"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39834"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39835"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39836"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39883"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-41178"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-41602"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-41889"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42499"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42501"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42502"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42504"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42505"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42506"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42507"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42508"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-43871"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-44503"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-46595"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-46597"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-46598"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-46600"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56852"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56853"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56855"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56858"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56859"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56860"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56862"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-73500"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-78662"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-84304"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-84445"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-259r-337f-4rfw"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-7j59-v9qr-6fq9"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-cp6g-7hqx-qxhp"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-hrxh-6v49-42gf"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-j88v-2chj-qfwx"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-p77j-4mvh-x3m3"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-pjcq-xvwq-hhpj"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-wf45-q9ch-q8gh"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-xmrv-pmrh-hhx2"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-2303"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25680"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25681"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27136"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27145"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32280"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32281"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32282"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32283"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32288"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32289"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32952"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33186"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33810"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33811"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33814"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33816"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33818"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-34040"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-34986"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39817"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39819"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39820"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39821"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39822"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39823"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39824"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39825"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39826"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39827"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39828"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39829"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39830"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39831"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39832"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39833"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39834"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39835"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39836"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39883"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41178"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41602"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41889"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42499"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42501"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42502"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42504"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42505"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42506"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42507"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42508"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-43871"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-44503"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46595"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46597"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46598"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46600"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56852"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56853"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56855"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56858"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56859"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56860"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56862"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-73500"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78662"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84304"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84445"
}
],
"related": [],
"schema_version": "1.7.3",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"type": "CVSS_V3"
}
],
"summary": "gRPC-Go is the Go language implementation of gRPC",
"upstream": [
"CVE-2026-2303",
"CVE-2026-25680",
"CVE-2026-25681",
"CVE-2026-27136",
"CVE-2026-27145",
"CVE-2026-32280",
"CVE-2026-32281",
"CVE-2026-32282",
"CVE-2026-32283",
"CVE-2026-32288",
"CVE-2026-32289",
"CVE-2026-32952",
"CVE-2026-33186",
"CVE-2026-33810",
"CVE-2026-33811",
"CVE-2026-33814",
"CVE-2026-33816",
"CVE-2026-33818",
"CVE-2026-34040",
"CVE-2026-34986",
"CVE-2026-39817",
"CVE-2026-39819",
"CVE-2026-39820",
"CVE-2026-39821",
"CVE-2026-39822",
"CVE-2026-39823",
"CVE-2026-39824",
"CVE-2026-39825",
"CVE-2026-39826",
"CVE-2026-39827",
"CVE-2026-39828",
"CVE-2026-39829",
"CVE-2026-39830",
"CVE-2026-39831",
"CVE-2026-39832",
"CVE-2026-39833",
"CVE-2026-39834",
"CVE-2026-39835",
"CVE-2026-39836",
"CVE-2026-39883",
"CVE-2026-41178",
"CVE-2026-41602",
"CVE-2026-41889",
"CVE-2026-42499",
"CVE-2026-42501",
"CVE-2026-42502",
"CVE-2026-42504",
"CVE-2026-42505",
"CVE-2026-42506",
"CVE-2026-42507",
"CVE-2026-42508",
"CVE-2026-43871",
"CVE-2026-44503",
"CVE-2026-46595",
"CVE-2026-46597",
"CVE-2026-46598",
"CVE-2026-46600",
"CVE-2026-56852",
"CVE-2026-56853",
"CVE-2026-56855",
"CVE-2026-56858",
"CVE-2026-56859",
"CVE-2026-56860",
"CVE-2026-56862",
"CVE-2026-73500",
"CVE-2026-78662",
"CVE-2026-84304",
"CVE-2026-84445",
"ghsa-259r-337f-4rfw",
"ghsa-7j59-v9qr-6fq9",
"ghsa-cp6g-7hqx-qxhp",
"ghsa-hrxh-6v49-42gf",
"ghsa-j88v-2chj-qfwx",
"ghsa-p77j-4mvh-x3m3",
"ghsa-pjcq-xvwq-hhpj",
"ghsa-wf45-q9ch-q8gh",
"ghsa-xmrv-pmrh-hhx2"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-KR69944 (CVE-2025-61732)
Vulnerability from cleanstart – Published: 2026-09-10 01:56 – Updated: 2026-09-18 11:59 – Source websiteMultiple security vulnerabilities affect the haproxy-ingress package. The source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for CVE-2026-46595. See references for individual vulnerability details.
| URL | Type | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "haproxy-ingress"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.15.1-r0"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"credits": [],
"database_specific": {},
"details": "Multiple security vulnerabilities affect the haproxy-ingress package. The source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for CVE-2026-46595. See references for individual vulnerability details.",
"id": "CLEANSTART-2026-KR69944",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-09-10T01:56:39.852336Z",
"references": [
{
"type": "ADVISORY",
"url": "https://github.com/cleanstart-dev/cleanstart-security-advisories/tree/main/advisories/2026/CLEANSTART-2026-KR69944.json"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-61732"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-68121"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-25679"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-25680"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-25681"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-27136"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-27139"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-27142"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-33814"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-33818"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39821"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39824"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39827"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39828"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39829"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39830"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39831"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39832"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39833"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39834"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39835"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42502"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42506"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42508"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-46595"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-46597"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-46598"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-46600"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56852"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56853"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56854"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56858"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56859"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56860"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56862"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-259r-337f-4rfw"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61732"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-68121"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25679"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25680"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25681"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27136"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27139"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27142"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33814"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33818"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39821"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39824"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39827"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39828"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39829"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39830"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39831"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39832"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39833"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39834"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39835"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42502"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42506"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42508"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46595"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46597"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46598"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46600"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56852"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56853"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56854"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56858"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56859"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56860"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56862"
}
],
"related": [],
"schema_version": "1.7.3",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"type": "CVSS_V3"
}
],
"summary": "source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for CVE-2...",
"upstream": [
"CVE-2025-61732",
"CVE-2025-68121",
"CVE-2026-25679",
"CVE-2026-25680",
"CVE-2026-25681",
"CVE-2026-27136",
"CVE-2026-27139",
"CVE-2026-27142",
"CVE-2026-33814",
"CVE-2026-33818",
"CVE-2026-39821",
"CVE-2026-39824",
"CVE-2026-39827",
"CVE-2026-39828",
"CVE-2026-39829",
"CVE-2026-39830",
"CVE-2026-39831",
"CVE-2026-39832",
"CVE-2026-39833",
"CVE-2026-39834",
"CVE-2026-39835",
"CVE-2026-42502",
"CVE-2026-42506",
"CVE-2026-42508",
"CVE-2026-46595",
"CVE-2026-46597",
"CVE-2026-46598",
"CVE-2026-46600",
"CVE-2026-56852",
"CVE-2026-56853",
"CVE-2026-56854",
"CVE-2026-56858",
"CVE-2026-56859",
"CVE-2026-56860",
"CVE-2026-56862",
"ghsa-259r-337f-4rfw"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-KT57055 (GHSA-259R-337F-4RFW)
Vulnerability from cleanstart – Published: 2026-08-13 12:10 – Updated: 2026-09-18 11:59 – Source websitePackage knative-serving version 1.20.3-r0 fixes 2 vulnerabilities: ghsa-259r-337f-4rfw, CVE-2026-41178
| URL | Type | |
|---|---|---|
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "knative-serving"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.20.3-r0"
}
],
"type": "ECOSYSTEM"
}
],
"versions": [
"1.20.3-r0"
]
}
],
"credits": [],
"database_specific": {},
"details": "Package knative-serving version 1.20.3-r0 fixes 2 vulnerabilities: ghsa-259r-337f-4rfw, CVE-2026-41178",
"id": "CLEANSTART-2026-KT57055",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-08-13T12:10:09Z",
"references": [
{
"type": "WEB",
"url": "https://knative.dev/docs/serving/"
}
],
"related": [],
"schema_version": "1.7.3",
"summary": "Security fixes in knative-serving 1.20.3-r0",
"upstream": [
"ghsa-259r-337f-4rfw",
"CVE-2026-41178"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-LC64978 (CVE-2026-26958)
Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source websitePackage tkn version 0.43.2-r1 fixes 59 vulnerabilities: CVE-2026-26958, CVE-2025-15558, CVE-2026-34040, CVE-2026-33997, CVE-2025-69725...
| URL | Type | |
|---|---|---|
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "tkn"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.43.2-r1"
}
],
"type": "ECOSYSTEM"
}
],
"versions": [
"0.43.2-r1"
]
}
],
"credits": [],
"database_specific": {},
"details": "Package tkn version 0.43.2-r1 fixes 59 vulnerabilities: CVE-2026-26958, CVE-2025-15558, CVE-2026-34040, CVE-2026-33997, CVE-2025-69725...",
"id": "CLEANSTART-2026-LC64978",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-09-01T11:17:16Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/tektoncd/cli"
}
],
"related": [],
"schema_version": "1.7.3",
"summary": "Security fixes in tkn 0.43.2-r1",
"upstream": [
"CVE-2026-26958",
"CVE-2025-15558",
"CVE-2026-34040",
"CVE-2026-33997",
"CVE-2025-69725",
"ghsa-gcjh-h69q-9w9g",
"ghsa-pmwq-pjrm-6p5r",
"CVE-2026-49478",
"CVE-2026-22772",
"CVE-2026-48702",
"CVE-2026-23831",
"CVE-2026-24117",
"CVE-2026-24137",
"CVE-2026-54787",
"CVE-2026-49834",
"CVE-2026-49835",
"CVE-2026-39984",
"CVE-2026-24686",
"CVE-2026-23991",
"CVE-2026-23992",
"CVE-2026-2303",
"CVE-2026-29181",
"CVE-2026-39883",
"CVE-2026-46597",
"CVE-2026-39828",
"CVE-2026-39829",
"CVE-2026-39830",
"CVE-2026-39831",
"CVE-2026-39832",
"CVE-2026-39835",
"CVE-2026-42508",
"CVE-2026-46595",
"CVE-2026-39827",
"CVE-2026-39833",
"CVE-2026-39834",
"CVE-2026-46598",
"CVE-2026-27136",
"CVE-2026-25681",
"CVE-2026-33814",
"CVE-2026-39821",
"CVE-2026-46600",
"CVE-2026-25680",
"CVE-2026-42502",
"CVE-2026-42506",
"CVE-2026-39824",
"CVE-2026-56852",
"ghsa-hrxh-6v49-42gf",
"CVE-2026-33818",
"CVE-2026-56853",
"CVE-2026-56858",
"CVE-2026-56859",
"CVE-2026-56860",
"CVE-2026-56862",
"CVE-2026-56864",
"CVE-2026-56865",
"ghsa-259r-337f-4rfw",
"ghsa-3fxj-6jh8-hvhx",
"ghsa-9g5q-2w5x-hmxf",
"ghsa-rjr7-jggh-pgcp"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-LE16402 (CVE-2026-50195)
Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source websitePackage rancher-agent version 2.13.7-r1 fixes 18 vulnerabilities: CVE-2026-50195, CVE-2026-53492, CVE-2026-53489, CVE-2026-46680, CVE-2026-53488...
| URL | Type | |
|---|---|---|
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "rancher-agent"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "2.13.7-r1"
}
],
"type": "ECOSYSTEM"
}
],
"versions": [
"2.13.7-r1"
]
}
],
"credits": [],
"database_specific": {},
"details": "Package rancher-agent version 2.13.7-r1 fixes 18 vulnerabilities: CVE-2026-50195, CVE-2026-53492, CVE-2026-53489, CVE-2026-46680, CVE-2026-53488...",
"id": "CLEANSTART-2026-LE16402",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-09-01T11:17:16Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/rancher/rancher"
}
],
"related": [],
"schema_version": "1.7.3",
"summary": "Security fixes in rancher-agent 2.13.7-r1",
"upstream": [
"CVE-2026-50195",
"CVE-2026-53492",
"CVE-2026-53489",
"CVE-2026-46680",
"CVE-2026-53488",
"CVE-2026-47262",
"ghsa-hrxh-6v49-42gf",
"CVE-2026-56864",
"CVE-2026-56865",
"CVE-2026-56852",
"CVE-2026-48978",
"CVE-2026-50163",
"CVE-2026-50151",
"CVE-2026-50162",
"ghsa-vh4v-2xq2-g5cg",
"ghsa-gcjh-h69q-9w9g",
"CVE-2026-41178",
"ghsa-259r-337f-4rfw"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-LE73008 (CVE-2025-61729)
Vulnerability from cleanstart – Published: 2026-09-10 00:49 – Updated: 2026-09-18 11:59 – Source websiteMultiple security vulnerabilities affect the prometheus-redis-exporter package. Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter value overflows the message buffer. See references for individual vulnerability details.
| URL | Type | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "prometheus-redis-exporter"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.86.0-r2"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"credits": [],
"database_specific": {},
"details": "Multiple security vulnerabilities affect the prometheus-redis-exporter package. Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter value overflows the message buffer. See references for individual vulnerability details.",
"id": "CLEANSTART-2026-LE73008",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-09-10T00:49:04.850219Z",
"references": [
{
"type": "ADVISORY",
"url": "https://github.com/cleanstart-dev/cleanstart-security-advisories/tree/main/advisories/2026/CLEANSTART-2026-LE73008.json"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-61729"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-33818"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39821"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39822"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42505"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-46600"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56853"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56858"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56859"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56860"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56862"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-259r-337f-4rfw"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61729"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33818"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39821"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39822"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42505"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46600"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56853"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56858"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56859"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56860"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56862"
}
],
"related": [],
"schema_version": "1.7.3",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"type": "CVSS_V3"
}
],
"summary": "Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter value overflows the message buffer",
"upstream": [
"CVE-2025-61729",
"CVE-2026-33818",
"CVE-2026-39821",
"CVE-2026-39822",
"CVE-2026-42505",
"CVE-2026-46600",
"CVE-2026-56853",
"CVE-2026-56858",
"CVE-2026-56859",
"CVE-2026-56860",
"CVE-2026-56862",
"ghsa-259r-337f-4rfw"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-LJ43739 (CVE-2026-14362)
Vulnerability from cleanstart – Published: 2026-09-08 00:47 – Updated: 2026-09-18 11:59 – Source websiteMultiple security vulnerabilities affect the weaviate-fips package. HashiCorp memberlist before version 0. See references for individual vulnerability details.
| URL | Type | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "weaviate-fips"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.38.6-r2"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"credits": [],
"database_specific": {},
"details": "Multiple security vulnerabilities affect the weaviate-fips package. HashiCorp memberlist before version 0. See references for individual vulnerability details.",
"id": "CLEANSTART-2026-LJ43739",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-09-08T00:47:15.121281Z",
"references": [
{
"type": "ADVISORY",
"url": "https://github.com/cleanstart-dev/cleanstart-security-advisories/tree/main/advisories/2026/CLEANSTART-2026-LJ43739.json"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-14362"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-2303"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-25680"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-25681"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-27136"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39821"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39827"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39828"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39829"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39830"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39831"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39832"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39833"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39834"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39835"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42502"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42506"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42508"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-46595"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-46597"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-46598"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-46600"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56852"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-259r-337f-4rfw"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-cp6g-7hqx-qxhp"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-14362"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-2303"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25680"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25681"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27136"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39821"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39827"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39828"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39829"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39830"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39831"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39832"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39833"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39834"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39835"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42502"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42506"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42508"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46595"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46597"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46598"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46600"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56852"
}
],
"related": [],
"schema_version": "1.7.3",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"type": "CVSS_V3"
}
],
"summary": "HashiCorp memberlist before version 0",
"upstream": [
"CVE-2026-14362",
"CVE-2026-2303",
"CVE-2026-25680",
"CVE-2026-25681",
"CVE-2026-27136",
"CVE-2026-39821",
"CVE-2026-39827",
"CVE-2026-39828",
"CVE-2026-39829",
"CVE-2026-39830",
"CVE-2026-39831",
"CVE-2026-39832",
"CVE-2026-39833",
"CVE-2026-39834",
"CVE-2026-39835",
"CVE-2026-42502",
"CVE-2026-42506",
"CVE-2026-42508",
"CVE-2026-46595",
"CVE-2026-46597",
"CVE-2026-46598",
"CVE-2026-46600",
"CVE-2026-56852",
"ghsa-259r-337f-4rfw",
"ghsa-cp6g-7hqx-qxhp"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-LJ97657 (CVE-2026-25680)
Vulnerability from cleanstart – Published: 2026-09-16 01:18 – Updated: 2026-09-18 11:59 – Source websiteMultiple security vulnerabilities affect the cadvisor package. Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. See references for individual vulnerability details.
| URL | Type | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "cadvisor"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.55.1-r7"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"credits": [],
"database_specific": {},
"details": "Multiple security vulnerabilities affect the cadvisor package. Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. See references for individual vulnerability details.",
"id": "CLEANSTART-2026-LJ97657",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-09-16T01:18:45.186561Z",
"references": [
{
"type": "ADVISORY",
"url": "https://github.com/cleanstart-dev/cleanstart-security-advisories/tree/main/advisories/2026/CLEANSTART-2026-LJ97657.json"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-25680"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-25681"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-27136"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-29181"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-33186"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-33814"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-33818"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39821"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39822"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39824"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39827"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39828"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39829"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39830"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39831"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39832"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39833"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39834"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39835"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-41178"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-41579"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42502"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42505"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42506"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42508"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-46595"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-46597"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-46598"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-46600"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56852"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56853"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56854"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56855"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56858"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56859"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56860"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56862"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-78662"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-84303"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-84304"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-84445"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-259r-337f-4rfw"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-hrxh-6v49-42gf"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25680"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25681"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27136"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-29181"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33186"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33814"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33818"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39821"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39822"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39824"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39827"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39828"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39829"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39830"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39831"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39832"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39833"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39834"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39835"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41178"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41579"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42502"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42505"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42506"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42508"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46595"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46597"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46598"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46600"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56852"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56853"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56854"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56855"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56858"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56859"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56860"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56862"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78662"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84303"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84304"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84445"
}
],
"related": [],
"schema_version": "1.7.3",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"type": "CVSS_V3"
}
],
"summary": "Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection",
"upstream": [
"CVE-2026-25680",
"CVE-2026-25681",
"CVE-2026-27136",
"CVE-2026-29181",
"CVE-2026-33186",
"CVE-2026-33814",
"CVE-2026-33818",
"CVE-2026-39821",
"CVE-2026-39822",
"CVE-2026-39824",
"CVE-2026-39827",
"CVE-2026-39828",
"CVE-2026-39829",
"CVE-2026-39830",
"CVE-2026-39831",
"CVE-2026-39832",
"CVE-2026-39833",
"CVE-2026-39834",
"CVE-2026-39835",
"CVE-2026-41178",
"CVE-2026-41579",
"CVE-2026-42502",
"CVE-2026-42505",
"CVE-2026-42506",
"CVE-2026-42508",
"CVE-2026-46595",
"CVE-2026-46597",
"CVE-2026-46598",
"CVE-2026-46600",
"CVE-2026-56852",
"CVE-2026-56853",
"CVE-2026-56854",
"CVE-2026-56855",
"CVE-2026-56858",
"CVE-2026-56859",
"CVE-2026-56860",
"CVE-2026-56862",
"CVE-2026-78662",
"CVE-2026-84303",
"CVE-2026-84304",
"CVE-2026-84445",
"ghsa-259r-337f-4rfw",
"ghsa-hrxh-6v49-42gf"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-LK25174 (CVE-2025-15558)
Vulnerability from cleanstart – Published: 2026-09-08 01:16 – Updated: 2026-09-18 11:59 – Source websiteMultiple security vulnerabilities affect the istio package. The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. See references for individual vulnerability details.
| URL | Type | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "istio"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.29.6-r2"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"credits": [],
"database_specific": {},
"details": "Multiple security vulnerabilities affect the istio package. The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. See references for individual vulnerability details.",
"id": "CLEANSTART-2026-LK25174",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-09-08T01:16:17.892966Z",
"references": [
{
"type": "ADVISORY",
"url": "https://github.com/cleanstart-dev/cleanstart-security-advisories/tree/main/advisories/2026/CLEANSTART-2026-LK25174.json"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-15558"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-25680"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-25681"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-27136"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-27145"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-33186"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-33811"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-33814"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-33818"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-35469"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39817"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39819"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39820"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39821"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39823"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39824"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39825"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39826"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39827"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39828"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39829"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39830"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39831"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39832"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39833"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39834"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39835"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39836"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-40179"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42151"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42154"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42499"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42501"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42502"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42504"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42506"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42507"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42508"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-44903"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-46595"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-46597"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-46598"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-46600"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56852"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56853"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56858"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56859"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56860"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56862"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-259r-337f-4rfw"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-8rm2-7qqf-34qm"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-fw8g-cg8f-9j28"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-gcjh-h69q-9w9g"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-hrxh-6v49-42gf"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-p436-gjf2-799p"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-p77j-4mvh-x3m3"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-vffh-x6r8-xx99"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-wg65-39gg-5wfj"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-15558"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25680"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25681"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27136"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27145"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33186"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33811"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33814"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33818"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-35469"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39817"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39819"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39820"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39821"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39823"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39824"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39825"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39826"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39827"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39828"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39829"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39830"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39831"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39832"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39833"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39834"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39835"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39836"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-40179"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42151"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42154"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42499"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42501"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42502"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42504"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42506"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42507"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42508"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-44903"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46595"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46597"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46598"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46600"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56852"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56853"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56858"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56859"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56860"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56862"
}
],
"related": [],
"schema_version": "1.7.3",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"type": "CVSS_V3"
}
],
"summary": "ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label",
"upstream": [
"CVE-2025-15558",
"CVE-2026-25680",
"CVE-2026-25681",
"CVE-2026-27136",
"CVE-2026-27145",
"CVE-2026-33186",
"CVE-2026-33811",
"CVE-2026-33814",
"CVE-2026-33818",
"CVE-2026-35469",
"CVE-2026-39817",
"CVE-2026-39819",
"CVE-2026-39820",
"CVE-2026-39821",
"CVE-2026-39823",
"CVE-2026-39824",
"CVE-2026-39825",
"CVE-2026-39826",
"CVE-2026-39827",
"CVE-2026-39828",
"CVE-2026-39829",
"CVE-2026-39830",
"CVE-2026-39831",
"CVE-2026-39832",
"CVE-2026-39833",
"CVE-2026-39834",
"CVE-2026-39835",
"CVE-2026-39836",
"CVE-2026-40179",
"CVE-2026-42151",
"CVE-2026-42154",
"CVE-2026-42499",
"CVE-2026-42501",
"CVE-2026-42502",
"CVE-2026-42504",
"CVE-2026-42506",
"CVE-2026-42507",
"CVE-2026-42508",
"CVE-2026-44903",
"CVE-2026-46595",
"CVE-2026-46597",
"CVE-2026-46598",
"CVE-2026-46600",
"CVE-2026-56852",
"CVE-2026-56853",
"CVE-2026-56858",
"CVE-2026-56859",
"CVE-2026-56860",
"CVE-2026-56862",
"ghsa-259r-337f-4rfw",
"ghsa-8rm2-7qqf-34qm",
"ghsa-fw8g-cg8f-9j28",
"ghsa-gcjh-h69q-9w9g",
"ghsa-hrxh-6v49-42gf",
"ghsa-p436-gjf2-799p",
"ghsa-p77j-4mvh-x3m3",
"ghsa-vffh-x6r8-xx99",
"ghsa-wg65-39gg-5wfj"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-LM38080 (GHSA-259R-337F-4RFW)
Vulnerability from cleanstart – Published: 2026-08-13 12:10 – Updated: 2026-09-18 11:59 – Source websitePackage elastic-beats version 9.3.9-r0 fixes 1 vulnerabilities: ghsa-259r-337f-4rfw
| URL | Type | |
|---|---|---|
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "elastic-beats"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "9.3.9-r0"
}
],
"type": "ECOSYSTEM"
}
],
"versions": [
"9.3.9-r0"
]
}
],
"credits": [],
"database_specific": {},
"details": "Package elastic-beats version 9.3.9-r0 fixes 1 vulnerabilities: ghsa-259r-337f-4rfw",
"id": "CLEANSTART-2026-LM38080",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-08-13T12:10:09Z",
"references": [
{
"type": "WEB",
"url": "https://www.elastic.co/products/beats"
}
],
"related": [],
"schema_version": "1.7.3",
"summary": "Security fixes in elastic-beats 9.3.9-r0",
"upstream": [
"ghsa-259r-337f-4rfw"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-LQ54152 (CVE-2026-33818)
Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source websitePackage ollama-fips version 0.32.11-r1 fixes 11 vulnerabilities: CVE-2026-33818, CVE-2026-56853, CVE-2026-56858, CVE-2026-56859, CVE-2026-56860...
| URL | Type | |
|---|---|---|
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "ollama-fips"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.32.11-r1"
}
],
"type": "ECOSYSTEM"
}
],
"versions": [
"0.32.11-r1"
]
}
],
"credits": [],
"database_specific": {},
"details": "Package ollama-fips version 0.32.11-r1 fixes 11 vulnerabilities: CVE-2026-33818, CVE-2026-56853, CVE-2026-56858, CVE-2026-56859, CVE-2026-56860...",
"id": "CLEANSTART-2026-LQ54152",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-09-01T11:17:16Z",
"references": [
{
"type": "WEB",
"url": "https://ollama.com"
}
],
"related": [],
"schema_version": "1.7.3",
"summary": "Security fixes in ollama-fips 0.32.11-r1",
"upstream": [
"CVE-2026-33818",
"CVE-2026-56853",
"CVE-2026-56858",
"CVE-2026-56859",
"CVE-2026-56860",
"CVE-2026-56862",
"CVE-2026-46600",
"CVE-2026-39821",
"CVE-2026-56864",
"CVE-2026-56865",
"ghsa-259r-337f-4rfw"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-ME39024 (CVE-2026-5724)
Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source websitePackage temporal-server version 1.29.7-r2 fixes 7 vulnerabilities: CVE-2026-5724, CVE-2025-14987, CVE-2025-14986, CVE-2026-5199, ghsa-hrxh-6v49-42gf...
| URL | Type | |
|---|---|---|
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "temporal-server"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.29.7-r2"
}
],
"type": "ECOSYSTEM"
}
],
"versions": [
"1.29.7-r2"
]
}
],
"credits": [],
"database_specific": {},
"details": "Package temporal-server version 1.29.7-r2 fixes 7 vulnerabilities: CVE-2026-5724, CVE-2025-14987, CVE-2025-14986, CVE-2026-5199, ghsa-hrxh-6v49-42gf...",
"id": "CLEANSTART-2026-ME39024",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-09-01T11:17:16Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/temporalio/temporal"
}
],
"related": [],
"schema_version": "1.7.3",
"summary": "Security fixes in temporal-server 1.29.7-r2",
"upstream": [
"CVE-2026-5724",
"CVE-2025-14987",
"CVE-2025-14986",
"CVE-2026-5199",
"ghsa-hrxh-6v49-42gf",
"CVE-2026-41178",
"ghsa-259r-337f-4rfw"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-MW79791 (GHSA-HRXH-6V49-42GF)
Vulnerability from cleanstart – Published: 2026-08-13 12:10 – Updated: 2026-09-18 11:59 – Source websitePackage prometheus version 3.13.1-r2 fixes 2 vulnerabilities: ghsa-hrxh-6v49-42gf, ghsa-259r-337f-4rfw
| URL | Type | |
|---|---|---|
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "prometheus"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "3.13.1-r2"
}
],
"type": "ECOSYSTEM"
}
],
"versions": [
"3.13.1-r2"
]
}
],
"credits": [],
"database_specific": {},
"details": "Package prometheus version 3.13.1-r2 fixes 2 vulnerabilities: ghsa-hrxh-6v49-42gf, ghsa-259r-337f-4rfw",
"id": "CLEANSTART-2026-MW79791",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-08-13T12:10:09Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/prometheus/prometheus"
}
],
"related": [],
"schema_version": "1.7.3",
"summary": "Security fixes in prometheus 3.13.1-r2",
"upstream": [
"ghsa-hrxh-6v49-42gf",
"ghsa-259r-337f-4rfw"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-NJ73427 (CVE-2026-39821)
Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source websitePackage tekton-chains-fips version 0.25.2-r1 fixes 31 vulnerabilities: CVE-2026-39821, CVE-2026-33818, CVE-2026-46600, CVE-2026-56853, CVE-2026-56858...
| URL | Type | |
|---|---|---|
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "tekton-chains-fips"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.25.2-r1"
}
],
"type": "ECOSYSTEM"
}
],
"versions": [
"0.25.2-r1"
]
}
],
"credits": [],
"database_specific": {},
"details": "Package tekton-chains-fips version 0.25.2-r1 fixes 31 vulnerabilities: CVE-2026-39821, CVE-2026-33818, CVE-2026-46600, CVE-2026-56853, CVE-2026-56858...",
"id": "CLEANSTART-2026-NJ73427",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-09-01T11:17:16Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/tektoncd/chains"
}
],
"related": [],
"schema_version": "1.7.3",
"summary": "Security fixes in tekton-chains-fips 0.25.2-r1",
"upstream": [
"CVE-2026-39821",
"CVE-2026-33818",
"CVE-2026-46600",
"CVE-2026-56853",
"CVE-2026-56858",
"CVE-2026-56859",
"CVE-2026-56860",
"CVE-2026-56862",
"ghsa-gcjh-h69q-9w9g",
"ghsa-pmwq-pjrm-6p5r",
"CVE-2026-49478",
"CVE-2026-48702",
"CVE-2026-54787",
"CVE-2026-49834",
"CVE-2026-49835",
"CVE-2026-39984",
"CVE-2026-40161",
"CVE-2026-40938",
"CVE-2026-25542",
"CVE-2026-40923",
"CVE-2026-40924",
"CVE-2026-2303",
"CVE-2026-39883",
"ghsa-hrxh-6v49-42gf",
"CVE-2026-56865",
"CVE-2026-56864",
"ghsa-259r-337f-4rfw",
"ghsa-rjr7-jggh-pgcp",
"ghsa-3fxj-6jh8-hvhx",
"ghsa-9g5q-2w5x-hmxf",
"CVE-2026-41178"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-NN12099 (CVE-2025-61732)
Vulnerability from cleanstart – Published: 2026-09-11 00:52 – Updated: 2026-09-18 11:59 – Source websiteMultiple security vulnerabilities affect the haproxy-ingress package. Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. See references for individual vulnerability details.
| URL | Type | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "haproxy-ingress"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.15.1-r0"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"credits": [],
"database_specific": {},
"details": "Multiple security vulnerabilities affect the haproxy-ingress package. Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. See references for individual vulnerability details.",
"id": "CLEANSTART-2026-NN12099",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-09-11T00:52:10.418800Z",
"references": [
{
"type": "ADVISORY",
"url": "https://github.com/cleanstart-dev/cleanstart-security-advisories/tree/main/advisories/2026/CLEANSTART-2026-NN12099.json"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-61732"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-68121"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-25679"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-25680"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-25681"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-27136"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-27139"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-27142"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-33814"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-33818"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39821"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39824"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39827"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39828"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39829"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39830"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39831"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39832"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39833"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39834"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39835"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42502"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42506"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42508"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-46595"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-46597"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-46598"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-46600"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56852"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56853"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56854"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56855"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56858"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56859"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56860"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56862"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-78662"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-259r-337f-4rfw"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61732"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-68121"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25679"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25680"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25681"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27136"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27139"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27142"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33814"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33818"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39821"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39824"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39827"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39828"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39829"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39830"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39831"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39832"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39833"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39834"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39835"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42502"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42506"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42508"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46595"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46597"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46598"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46600"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56852"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56853"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56854"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56855"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56858"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56859"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56860"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56862"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78662"
}
],
"related": [],
"schema_version": "1.7.3",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"type": "CVSS_V3"
}
],
"summary": "Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection",
"upstream": [
"CVE-2025-61732",
"CVE-2025-68121",
"CVE-2026-25679",
"CVE-2026-25680",
"CVE-2026-25681",
"CVE-2026-27136",
"CVE-2026-27139",
"CVE-2026-27142",
"CVE-2026-33814",
"CVE-2026-33818",
"CVE-2026-39821",
"CVE-2026-39824",
"CVE-2026-39827",
"CVE-2026-39828",
"CVE-2026-39829",
"CVE-2026-39830",
"CVE-2026-39831",
"CVE-2026-39832",
"CVE-2026-39833",
"CVE-2026-39834",
"CVE-2026-39835",
"CVE-2026-42502",
"CVE-2026-42506",
"CVE-2026-42508",
"CVE-2026-46595",
"CVE-2026-46597",
"CVE-2026-46598",
"CVE-2026-46600",
"CVE-2026-56852",
"CVE-2026-56853",
"CVE-2026-56854",
"CVE-2026-56855",
"CVE-2026-56858",
"CVE-2026-56859",
"CVE-2026-56860",
"CVE-2026-56862",
"CVE-2026-78662",
"ghsa-259r-337f-4rfw"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-NO03449 (GHSA-259R-337F-4RFW)
Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source websitePackage ollama-fips version 0.32.9-r2 fixes 1 vulnerabilities: ghsa-259r-337f-4rfw
| URL | Type | |
|---|---|---|
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "ollama-fips"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.32.9-r2"
}
],
"type": "ECOSYSTEM"
}
],
"versions": [
"0.32.9-r2"
]
}
],
"credits": [],
"database_specific": {},
"details": "Package ollama-fips version 0.32.9-r2 fixes 1 vulnerabilities: ghsa-259r-337f-4rfw",
"id": "CLEANSTART-2026-NO03449",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-09-01T11:17:16Z",
"references": [
{
"type": "WEB",
"url": "https://ollama.com"
}
],
"related": [],
"schema_version": "1.7.3",
"summary": "Security fixes in ollama-fips 0.32.9-r2",
"upstream": [
"ghsa-259r-337f-4rfw"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-NR19543 (GHSA-HRXH-6V49-42GF)
Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source websitePackage prometheus-fips version 3.10.0-r1 fixes 3 vulnerabilities: ghsa-hrxh-6v49-42gf, CVE-2026-2303, ghsa-259r-337f-4rfw
| URL | Type | |
|---|---|---|
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "prometheus-fips"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "3.10.0-r1"
}
],
"type": "ECOSYSTEM"
}
],
"versions": [
"3.10.0-r1"
]
}
],
"credits": [],
"database_specific": {},
"details": "Package prometheus-fips version 3.10.0-r1 fixes 3 vulnerabilities: ghsa-hrxh-6v49-42gf, CVE-2026-2303, ghsa-259r-337f-4rfw",
"id": "CLEANSTART-2026-NR19543",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-09-01T11:17:16Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/prometheus/prometheus"
}
],
"related": [],
"schema_version": "1.7.3",
"summary": "Security fixes in prometheus-fips 3.10.0-r1",
"upstream": [
"ghsa-hrxh-6v49-42gf",
"CVE-2026-2303",
"ghsa-259r-337f-4rfw"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-NY04600 (GHSA-259R-337F-4RFW)
Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source websitePackage argo-cd version 3.3.14-r2 fixes 1 vulnerabilities: ghsa-259r-337f-4rfw
| URL | Type | |
|---|---|---|
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "argo-cd"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "3.3.14-r2"
}
],
"type": "ECOSYSTEM"
}
],
"versions": [
"3.3.14-r2"
]
}
],
"credits": [],
"database_specific": {},
"details": "Package argo-cd version 3.3.14-r2 fixes 1 vulnerabilities: ghsa-259r-337f-4rfw",
"id": "CLEANSTART-2026-NY04600",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-09-01T11:17:16Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/argoproj/argo-cd"
}
],
"related": [],
"schema_version": "1.7.3",
"summary": "Security fixes in argo-cd 3.3.14-r2",
"upstream": [
"ghsa-259r-337f-4rfw"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-NZ51335 (CVE-2026-33818)
Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source websitePackage tekton-chains-fips version 0.26.5-r1 fixes 25 vulnerabilities: CVE-2026-33818, CVE-2026-46600, CVE-2026-56853, CVE-2026-56858, CVE-2026-56859...
| URL | Type | |
|---|---|---|
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "tekton-chains-fips"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.26.5-r1"
}
],
"type": "ECOSYSTEM"
}
],
"versions": [
"0.26.5-r1"
]
}
],
"credits": [],
"database_specific": {},
"details": "Package tekton-chains-fips version 0.26.5-r1 fixes 25 vulnerabilities: CVE-2026-33818, CVE-2026-46600, CVE-2026-56853, CVE-2026-56858, CVE-2026-56859...",
"id": "CLEANSTART-2026-NZ51335",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-09-01T11:17:16Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/tektoncd/chains"
}
],
"related": [],
"schema_version": "1.7.3",
"summary": "Security fixes in tekton-chains-fips 0.26.5-r1",
"upstream": [
"CVE-2026-33818",
"CVE-2026-46600",
"CVE-2026-56853",
"CVE-2026-56858",
"CVE-2026-56859",
"CVE-2026-56860",
"CVE-2026-56862",
"CVE-2026-39821",
"ghsa-gcjh-h69q-9w9g",
"CVE-2026-49478",
"CVE-2026-48702",
"CVE-2026-54787",
"CVE-2026-49834",
"CVE-2026-49835",
"CVE-2026-39984",
"CVE-2026-2303",
"CVE-2026-39883",
"ghsa-hrxh-6v49-42gf",
"CVE-2026-56864",
"CVE-2026-56865",
"ghsa-259r-337f-4rfw",
"ghsa-3fxj-6jh8-hvhx",
"ghsa-9g5q-2w5x-hmxf",
"ghsa-rjr7-jggh-pgcp",
"CVE-2026-41178"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-OO93790 (GHSA-HRXH-6V49-42GF)
Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source websitePackage argo-cd version 3.4.6-r0 fixes 3 vulnerabilities: ghsa-hrxh-6v49-42gf, ghsa-259r-337f-4rfw, CVE-2026-41178
| URL | Type | |
|---|---|---|
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "argo-cd"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "3.4.6-r0"
}
],
"type": "ECOSYSTEM"
}
],
"versions": [
"3.4.6-r0"
]
}
],
"credits": [],
"database_specific": {},
"details": "Package argo-cd version 3.4.6-r0 fixes 3 vulnerabilities: ghsa-hrxh-6v49-42gf, ghsa-259r-337f-4rfw, CVE-2026-41178",
"id": "CLEANSTART-2026-OO93790",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-09-01T11:17:16Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/argoproj/argo-cd"
}
],
"related": [],
"schema_version": "1.7.3",
"summary": "Security fixes in argo-cd 3.4.6-r0",
"upstream": [
"ghsa-hrxh-6v49-42gf",
"ghsa-259r-337f-4rfw",
"CVE-2026-41178"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-OO99794 (CVE-2026-56860)
Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source websitePackage argo-cd-fips version 3.4.7-r1 fixes 13 vulnerabilities: CVE-2026-56860, CVE-2026-56858, CVE-2026-33818, CVE-2026-56853, CVE-2026-56859...
| URL | Type | |
|---|---|---|
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "argo-cd-fips"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "3.4.7-r1"
}
],
"type": "ECOSYSTEM"
}
],
"versions": [
"3.4.7-r1"
]
}
],
"credits": [],
"database_specific": {},
"details": "Package argo-cd-fips version 3.4.7-r1 fixes 13 vulnerabilities: CVE-2026-56860, CVE-2026-56858, CVE-2026-33818, CVE-2026-56853, CVE-2026-56859...",
"id": "CLEANSTART-2026-OO99794",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-09-01T11:17:16Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/argoproj/argo-cd"
}
],
"related": [],
"schema_version": "1.7.3",
"summary": "Security fixes in argo-cd-fips 3.4.7-r1",
"upstream": [
"CVE-2026-56860",
"CVE-2026-56858",
"CVE-2026-33818",
"CVE-2026-56853",
"CVE-2026-56859",
"CVE-2026-56862",
"CVE-2026-39821",
"CVE-2026-46600",
"CVE-2026-50163",
"CVE-2026-71556",
"CVE-2026-71557",
"ghsa-259r-337f-4rfw",
"CVE-2026-56852"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-OS02559 (CVE-2026-50195)
Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source websitePackage rancher-fleet-agent version 0.16.1-r1 fixes 40 vulnerabilities: CVE-2026-50195, CVE-2026-53492, CVE-2026-46680, CVE-2026-53488, CVE-2026-53489...
| URL | Type | |
|---|---|---|
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "rancher-fleet-agent"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.16.1-r1"
}
],
"type": "ECOSYSTEM"
}
],
"versions": [
"0.16.1-r1"
]
}
],
"credits": [],
"database_specific": {},
"details": "Package rancher-fleet-agent version 0.16.1-r1 fixes 40 vulnerabilities: CVE-2026-50195, CVE-2026-53492, CVE-2026-46680, CVE-2026-53488, CVE-2026-53489...",
"id": "CLEANSTART-2026-OS02559",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-09-01T11:17:16Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/rancher/fleet"
}
],
"related": [],
"schema_version": "1.7.3",
"summary": "Security fixes in rancher-fleet-agent 0.16.1-r1",
"upstream": [
"CVE-2026-50195",
"CVE-2026-53492",
"CVE-2026-46680",
"CVE-2026-53488",
"CVE-2026-53489",
"CVE-2026-47262",
"CVE-2026-42508",
"CVE-2026-39835",
"CVE-2026-46598",
"CVE-2026-39828",
"CVE-2026-39829",
"CVE-2026-46597",
"CVE-2026-39830",
"CVE-2026-39831",
"CVE-2026-39832",
"CVE-2026-39833",
"CVE-2026-39834",
"CVE-2026-46595",
"CVE-2026-39827",
"CVE-2026-33186",
"ghsa-hrxh-6v49-42gf",
"CVE-2026-25681",
"CVE-2026-27136",
"CVE-2026-33814",
"CVE-2026-46600",
"CVE-2026-39821",
"CVE-2026-42502",
"CVE-2026-42506",
"CVE-2026-25680",
"CVE-2026-29181",
"CVE-2026-35469",
"CVE-2026-56852",
"CVE-2026-48978",
"CVE-2026-50163",
"CVE-2026-50151",
"CVE-2026-50162",
"ghsa-vh4v-2xq2-g5cg",
"CVE-2026-39824",
"CVE-2026-35206",
"ghsa-259r-337f-4rfw"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-PB67247 (CVE-2026-56860)
Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source websitePackage temporal-server version 1.30.6-r2 fixes 11 vulnerabilities: CVE-2026-56860, CVE-2026-56858, CVE-2026-33818, CVE-2026-46600, CVE-2026-56853...
| URL | Type | |
|---|---|---|
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "temporal-server"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.30.6-r2"
}
],
"type": "ECOSYSTEM"
}
],
"versions": [
"1.30.6-r2"
]
}
],
"credits": [],
"database_specific": {},
"details": "Package temporal-server version 1.30.6-r2 fixes 11 vulnerabilities: CVE-2026-56860, CVE-2026-56858, CVE-2026-33818, CVE-2026-46600, CVE-2026-56853...",
"id": "CLEANSTART-2026-PB67247",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-09-01T11:17:16Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/temporalio/temporal"
}
],
"related": [],
"schema_version": "1.7.3",
"summary": "Security fixes in temporal-server 1.30.6-r2",
"upstream": [
"CVE-2026-56860",
"CVE-2026-56858",
"CVE-2026-33818",
"CVE-2026-46600",
"CVE-2026-56853",
"CVE-2026-56859",
"CVE-2026-56862",
"CVE-2026-39821",
"ghsa-hrxh-6v49-42gf",
"CVE-2026-41178",
"ghsa-259r-337f-4rfw"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-PC33523 (CVE-2026-2303)
Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source websitePackage karma version 0.128-r1 fixes 6 vulnerabilities: CVE-2026-2303, CVE-2026-39824, ghsa-259r-337f-4rfw, ghsa-3fxj-6jh8-hvhx, ghsa-9g5q-2w5x-hmxf...
| URL | Type | |
|---|---|---|
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "karma"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.128-r1"
}
],
"type": "ECOSYSTEM"
}
],
"versions": [
"0.128-r1"
]
}
],
"credits": [],
"database_specific": {},
"details": "Package karma version 0.128-r1 fixes 6 vulnerabilities: CVE-2026-2303, CVE-2026-39824, ghsa-259r-337f-4rfw, ghsa-3fxj-6jh8-hvhx, ghsa-9g5q-2w5x-hmxf...",
"id": "CLEANSTART-2026-PC33523",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-09-01T11:17:16Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/prymitive/karma.git"
}
],
"related": [],
"schema_version": "1.7.3",
"summary": "Security fixes in karma 0.128-r1",
"upstream": [
"CVE-2026-2303",
"CVE-2026-39824",
"ghsa-259r-337f-4rfw",
"ghsa-3fxj-6jh8-hvhx",
"ghsa-9g5q-2w5x-hmxf",
"ghsa-rjr7-jggh-pgcp"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-PE88816 (CVE-2025-47912)
Vulnerability from cleanstart – Published: 2026-09-08 01:30 – Updated: 2026-09-18 11:59 – Source websiteMultiple security vulnerabilities affect the helm-operator package. The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. See references for individual vulnerability details.
| URL | Type | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "helm-operator"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.42.2-r2"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"credits": [],
"database_specific": {},
"details": "Multiple security vulnerabilities affect the helm-operator package. The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. See references for individual vulnerability details.",
"id": "CLEANSTART-2026-PE88816",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-09-08T01:30:18.355188Z",
"references": [
{
"type": "ADVISORY",
"url": "https://github.com/cleanstart-dev/cleanstart-security-advisories/tree/main/advisories/2026/CLEANSTART-2026-PE88816.json"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-47912"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-58183"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-58185"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-58186"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-58187"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-58188"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-58189"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-61723"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-61724"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-61725"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-61729"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-25680"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-25681"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-27136"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-27140"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-27143"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-27144"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-27145"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-29181"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-32280"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-32281"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-32282"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-32283"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-32288"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-32289"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-33811"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-33814"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-33818"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-35206"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-35469"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39817"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39819"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39820"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39821"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39823"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39824"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39825"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39826"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39827"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39828"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39829"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39830"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39831"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39832"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39833"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39834"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39835"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39836"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39883"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-41178"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42499"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42501"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42502"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42504"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42506"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42507"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42508"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-46595"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-46597"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-46598"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-46600"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-46680"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-47262"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-50163"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-53488"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56853"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56858"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56859"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56860"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56862"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-259r-337f-4rfw"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-fqw6-gf59-qr4w"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-gcjh-h69q-9w9g"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-hfvc-g4fc-pqhx"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-hr2v-4r36-88hr"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-hrxh-6v49-42gf"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-jpcc-p29g-p8mq"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-mh2q-q3fh-2475"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-pc3f-x583-g7j2"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-xhf5-7wjv-pqxp"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47912"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58183"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58185"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58186"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58187"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58188"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58189"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61723"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61724"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61725"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61729"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25680"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25681"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27136"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27140"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27143"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27144"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27145"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-29181"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32280"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32281"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32282"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32283"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32288"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32289"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33811"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33814"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33818"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-35206"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-35469"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39817"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39819"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39820"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39821"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39823"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39824"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39825"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39826"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39827"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39828"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39829"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39830"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39831"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39832"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39833"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39834"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39835"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39836"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39883"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41178"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42499"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42501"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42502"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42504"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42506"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42507"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42508"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46595"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46597"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46598"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46600"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46680"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-47262"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-50163"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-53488"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56853"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56858"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56859"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56860"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56862"
}
],
"related": [],
"schema_version": "1.7.3",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"type": "CVSS_V3"
}
],
"summary": "ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label",
"upstream": [
"CVE-2025-47912",
"CVE-2025-58183",
"CVE-2025-58185",
"CVE-2025-58186",
"CVE-2025-58187",
"CVE-2025-58188",
"CVE-2025-58189",
"CVE-2025-61723",
"CVE-2025-61724",
"CVE-2025-61725",
"CVE-2025-61729",
"CVE-2026-25680",
"CVE-2026-25681",
"CVE-2026-27136",
"CVE-2026-27140",
"CVE-2026-27143",
"CVE-2026-27144",
"CVE-2026-27145",
"CVE-2026-29181",
"CVE-2026-32280",
"CVE-2026-32281",
"CVE-2026-32282",
"CVE-2026-32283",
"CVE-2026-32288",
"CVE-2026-32289",
"CVE-2026-33811",
"CVE-2026-33814",
"CVE-2026-33818",
"CVE-2026-35206",
"CVE-2026-35469",
"CVE-2026-39817",
"CVE-2026-39819",
"CVE-2026-39820",
"CVE-2026-39821",
"CVE-2026-39823",
"CVE-2026-39824",
"CVE-2026-39825",
"CVE-2026-39826",
"CVE-2026-39827",
"CVE-2026-39828",
"CVE-2026-39829",
"CVE-2026-39830",
"CVE-2026-39831",
"CVE-2026-39832",
"CVE-2026-39833",
"CVE-2026-39834",
"CVE-2026-39835",
"CVE-2026-39836",
"CVE-2026-39883",
"CVE-2026-41178",
"CVE-2026-42499",
"CVE-2026-42501",
"CVE-2026-42502",
"CVE-2026-42504",
"CVE-2026-42506",
"CVE-2026-42507",
"CVE-2026-42508",
"CVE-2026-46595",
"CVE-2026-46597",
"CVE-2026-46598",
"CVE-2026-46600",
"CVE-2026-46680",
"CVE-2026-47262",
"CVE-2026-50163",
"CVE-2026-53488",
"CVE-2026-56853",
"CVE-2026-56858",
"CVE-2026-56859",
"CVE-2026-56860",
"CVE-2026-56862",
"ghsa-259r-337f-4rfw",
"ghsa-fqw6-gf59-qr4w",
"ghsa-gcjh-h69q-9w9g",
"ghsa-hfvc-g4fc-pqhx",
"ghsa-hr2v-4r36-88hr",
"ghsa-hrxh-6v49-42gf",
"ghsa-jpcc-p29g-p8mq",
"ghsa-mh2q-q3fh-2475",
"ghsa-pc3f-x583-g7j2",
"ghsa-xhf5-7wjv-pqxp"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-PL26831 (CVE-2026-56860)
Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source websitePackage temporal-server version 1.30.6-r3 fixes 11 vulnerabilities: CVE-2026-56860, CVE-2026-56858, CVE-2026-33818, CVE-2026-46600, CVE-2026-56853...
| URL | Type | |
|---|---|---|
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "temporal-server"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.30.6-r3"
}
],
"type": "ECOSYSTEM"
}
],
"versions": [
"1.30.6-r3"
]
}
],
"credits": [],
"database_specific": {},
"details": "Package temporal-server version 1.30.6-r3 fixes 11 vulnerabilities: CVE-2026-56860, CVE-2026-56858, CVE-2026-33818, CVE-2026-46600, CVE-2026-56853...",
"id": "CLEANSTART-2026-PL26831",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-09-01T11:17:16Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/temporalio/temporal"
}
],
"related": [],
"schema_version": "1.7.3",
"summary": "Security fixes in temporal-server 1.30.6-r3",
"upstream": [
"CVE-2026-56860",
"CVE-2026-56858",
"CVE-2026-33818",
"CVE-2026-46600",
"CVE-2026-56853",
"CVE-2026-56859",
"CVE-2026-56862",
"CVE-2026-39821",
"ghsa-hrxh-6v49-42gf",
"CVE-2026-41178",
"ghsa-259r-337f-4rfw"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-PM77605 (CVE-2023-3955)
Vulnerability from cleanstart – Published: 2026-08-13 12:10 – Updated: 2026-09-18 11:59 – Source websitePackage flux-notification-controller-fips version 1.9.2-r0 fixes 6 vulnerabilities: CVE-2023-3955, CVE-2023-3676, CVE-2019-11250, ghsa-gcjh-h69q-9w9g, ghsa-259r-337f-4rfw...
| URL | Type | |
|---|---|---|
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "flux-notification-controller-fips"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.9.2-r0"
}
],
"type": "ECOSYSTEM"
}
],
"versions": [
"1.9.2-r0"
]
}
],
"credits": [],
"database_specific": {},
"details": "Package flux-notification-controller-fips version 1.9.2-r0 fixes 6 vulnerabilities: CVE-2023-3955, CVE-2023-3676, CVE-2019-11250, ghsa-gcjh-h69q-9w9g, ghsa-259r-337f-4rfw...",
"id": "CLEANSTART-2026-PM77605",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-08-13T12:10:09Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/fluxcd/notification-controller"
}
],
"related": [],
"schema_version": "1.7.3",
"summary": "Security fixes in flux-notification-controller-fips 1.9.2-r0",
"upstream": [
"CVE-2023-3955",
"CVE-2023-3676",
"CVE-2019-11250",
"ghsa-gcjh-h69q-9w9g",
"ghsa-259r-337f-4rfw",
"ghsa-hrxh-6v49-42gf"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-PO42401 (CVE-2026-53492)
Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source websitePackage rancher-fleet-agent version 0.15.4-r1 fixes 39 vulnerabilities: CVE-2026-53492, CVE-2026-50195, CVE-2026-53489, CVE-2026-46680, CVE-2026-53488...
| URL | Type | |
|---|---|---|
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "rancher-fleet-agent"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.15.4-r1"
}
],
"type": "ECOSYSTEM"
}
],
"versions": [
"0.15.4-r1"
]
}
],
"credits": [],
"database_specific": {},
"details": "Package rancher-fleet-agent version 0.15.4-r1 fixes 39 vulnerabilities: CVE-2026-53492, CVE-2026-50195, CVE-2026-53489, CVE-2026-46680, CVE-2026-53488...",
"id": "CLEANSTART-2026-PO42401",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-09-01T11:17:16Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/rancher/fleet"
}
],
"related": [],
"schema_version": "1.7.3",
"summary": "Security fixes in rancher-fleet-agent 0.15.4-r1",
"upstream": [
"CVE-2026-53492",
"CVE-2026-50195",
"CVE-2026-53489",
"CVE-2026-46680",
"CVE-2026-53488",
"CVE-2026-47262",
"CVE-2026-42508",
"CVE-2026-39835",
"CVE-2026-46598",
"CVE-2026-39828",
"CVE-2026-39829",
"CVE-2026-46597",
"CVE-2026-39830",
"CVE-2026-39831",
"CVE-2026-39832",
"CVE-2026-39833",
"CVE-2026-39834",
"CVE-2026-46595",
"CVE-2026-39827",
"CVE-2026-33186",
"ghsa-hrxh-6v49-42gf",
"CVE-2026-46600",
"CVE-2026-25681",
"CVE-2026-27136",
"CVE-2026-39821",
"CVE-2026-42502",
"CVE-2026-42506",
"CVE-2026-25680",
"CVE-2026-29181",
"CVE-2026-35469",
"CVE-2026-56852",
"CVE-2026-50163",
"CVE-2026-48978",
"CVE-2026-50151",
"CVE-2026-50162",
"ghsa-vh4v-2xq2-g5cg",
"CVE-2026-39824",
"CVE-2026-35206",
"ghsa-259r-337f-4rfw"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-PP67363 (CVE-2026-41178)
Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source websitePackage newrelic-infrastructure-agent version 1.79.0-r1 fixes 2 vulnerabilities: CVE-2026-41178, ghsa-259r-337f-4rfw
| URL | Type | |
|---|---|---|
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "newrelic-infrastructure-agent"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.79.0-r1"
}
],
"type": "ECOSYSTEM"
}
],
"versions": [
"1.79.0-r1"
]
}
],
"credits": [],
"database_specific": {},
"details": "Package newrelic-infrastructure-agent version 1.79.0-r1 fixes 2 vulnerabilities: CVE-2026-41178, ghsa-259r-337f-4rfw",
"id": "CLEANSTART-2026-PP67363",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-09-01T11:17:16Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/newrelic/infrastructure-agent"
}
],
"related": [],
"schema_version": "1.7.3",
"summary": "Security fixes in newrelic-infrastructure-agent 1.79.0-r1",
"upstream": [
"CVE-2026-41178",
"ghsa-259r-337f-4rfw"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-PY48265 (CVE-2026-56860)
Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source websitePackage temporal-server version 1.30.6-r1 fixes 15 vulnerabilities: CVE-2026-56860, CVE-2026-56858, CVE-2026-33818, CVE-2026-46600, CVE-2026-56853...
| URL | Type | |
|---|---|---|
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "temporal-server"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.30.6-r1"
}
],
"type": "ECOSYSTEM"
}
],
"versions": [
"1.30.6-r1"
]
}
],
"credits": [],
"database_specific": {},
"details": "Package temporal-server version 1.30.6-r1 fixes 15 vulnerabilities: CVE-2026-56860, CVE-2026-56858, CVE-2026-33818, CVE-2026-46600, CVE-2026-56853...",
"id": "CLEANSTART-2026-PY48265",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-09-01T11:17:16Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/temporalio/temporal"
}
],
"related": [],
"schema_version": "1.7.3",
"summary": "Security fixes in temporal-server 1.30.6-r1",
"upstream": [
"CVE-2026-56860",
"CVE-2026-56858",
"CVE-2026-33818",
"CVE-2026-46600",
"CVE-2026-56853",
"CVE-2026-56859",
"CVE-2026-56862",
"CVE-2026-39821",
"CVE-2026-5724",
"CVE-2025-14987",
"CVE-2025-14986",
"CVE-2026-5199",
"ghsa-hrxh-6v49-42gf",
"CVE-2026-41178",
"ghsa-259r-337f-4rfw"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-QB39018 (CVE-2026-50195)
Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source websitePackage rancher-fleet-agent version 0.14.10-r1 fixes 40 vulnerabilities: CVE-2026-50195, CVE-2026-53492, CVE-2026-46680, CVE-2026-53488, CVE-2026-53489...
| URL | Type | |
|---|---|---|
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "rancher-fleet-agent"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.14.10-r1"
}
],
"type": "ECOSYSTEM"
}
],
"versions": [
"0.14.10-r1"
]
}
],
"credits": [],
"database_specific": {},
"details": "Package rancher-fleet-agent version 0.14.10-r1 fixes 40 vulnerabilities: CVE-2026-50195, CVE-2026-53492, CVE-2026-46680, CVE-2026-53488, CVE-2026-53489...",
"id": "CLEANSTART-2026-QB39018",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-09-01T11:17:16Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/rancher/fleet"
}
],
"related": [],
"schema_version": "1.7.3",
"summary": "Security fixes in rancher-fleet-agent 0.14.10-r1",
"upstream": [
"CVE-2026-50195",
"CVE-2026-53492",
"CVE-2026-46680",
"CVE-2026-53488",
"CVE-2026-53489",
"CVE-2026-47262",
"CVE-2026-42508",
"CVE-2026-39835",
"CVE-2026-46598",
"CVE-2026-39828",
"CVE-2026-39829",
"CVE-2026-46597",
"CVE-2026-39830",
"CVE-2026-39831",
"CVE-2026-39832",
"CVE-2026-39833",
"CVE-2026-39834",
"CVE-2026-46595",
"CVE-2026-39827",
"CVE-2026-33186",
"ghsa-hrxh-6v49-42gf",
"CVE-2026-25681",
"CVE-2026-27136",
"CVE-2026-33814",
"CVE-2026-46600",
"CVE-2026-39821",
"CVE-2026-42502",
"CVE-2026-42506",
"CVE-2026-25680",
"CVE-2026-29181",
"CVE-2026-35469",
"CVE-2026-56852",
"CVE-2026-48978",
"CVE-2026-50163",
"CVE-2026-50151",
"CVE-2026-50162",
"ghsa-vh4v-2xq2-g5cg",
"CVE-2026-35206",
"ghsa-259r-337f-4rfw",
"CVE-2026-39824"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-QK25151 (CVE-2025-61726)
Vulnerability from cleanstart – Published: 2026-09-08 01:53 – Updated: 2026-09-18 11:59 – Source websiteMultiple security vulnerabilities affect the step-issuer package. Previously, a channel registered in the mux's chanList is not usable until it is established. See references for individual vulnerability details.
| URL | Type | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "step-issuer"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.9.11-r4"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"credits": [],
"database_specific": {},
"details": "Multiple security vulnerabilities affect the step-issuer package. Previously, a channel registered in the mux\u0027s chanList is not usable until it is established. See references for individual vulnerability details.",
"id": "CLEANSTART-2026-QK25151",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-09-08T01:53:49.601507Z",
"references": [
{
"type": "ADVISORY",
"url": "https://github.com/cleanstart-dev/cleanstart-security-advisories/tree/main/advisories/2026/CLEANSTART-2026-QK25151.json"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-61726"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-61728"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-61730"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-68121"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-69725"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-25518"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-25679"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-25680"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-25681"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-25793"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-26958"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-27136"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-27139"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-27142"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-27145"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-29181"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-30836"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-32280"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-32281"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-32282"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-32283"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-32288"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-32289"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-33186"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-33811"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-33814"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-33815"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-33816"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-33818"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-34986"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39820"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39821"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39822"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39823"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39824"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39825"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39826"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39827"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39828"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39829"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39830"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39831"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39832"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39833"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39834"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39835"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39836"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-40097"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-41178"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-41889"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42499"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42502"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42504"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42505"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42506"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42507"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42508"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-46595"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-46597"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-46598"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-46600"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56852"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56853"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56854"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56855"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56858"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56859"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56860"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56862"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-78662"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-84304"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-259r-337f-4rfw"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-3fxj-6jh8-hvhx"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-9g5q-2w5x-hmxf"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-hrxh-6v49-42gf"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-rjr7-jggh-pgcp"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61726"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61728"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61730"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-68121"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-69725"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25518"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25679"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25680"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25681"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25793"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-26958"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27136"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27139"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27142"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27145"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-29181"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-30836"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32280"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32281"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32282"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32283"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32288"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32289"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33186"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33811"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33814"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33815"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33816"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33818"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-34986"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39820"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39821"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39822"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39823"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39824"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39825"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39826"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39827"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39828"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39829"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39830"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39831"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39832"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39833"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39834"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39835"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39836"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-40097"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41178"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41889"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42499"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42502"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42504"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42505"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42506"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42507"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42508"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46595"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46597"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46598"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46600"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56852"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56853"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56854"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56855"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56858"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56859"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56860"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56862"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78662"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84304"
}
],
"related": [],
"schema_version": "1.7.3",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"type": "CVSS_V3"
}
],
"summary": "Previously, a channel registered in the mux\u0027s chanList is not usable until it is established",
"upstream": [
"CVE-2025-61726",
"CVE-2025-61728",
"CVE-2025-61730",
"CVE-2025-68121",
"CVE-2025-69725",
"CVE-2026-25518",
"CVE-2026-25679",
"CVE-2026-25680",
"CVE-2026-25681",
"CVE-2026-25793",
"CVE-2026-26958",
"CVE-2026-27136",
"CVE-2026-27139",
"CVE-2026-27142",
"CVE-2026-27145",
"CVE-2026-29181",
"CVE-2026-30836",
"CVE-2026-32280",
"CVE-2026-32281",
"CVE-2026-32282",
"CVE-2026-32283",
"CVE-2026-32288",
"CVE-2026-32289",
"CVE-2026-33186",
"CVE-2026-33811",
"CVE-2026-33814",
"CVE-2026-33815",
"CVE-2026-33816",
"CVE-2026-33818",
"CVE-2026-34986",
"CVE-2026-39820",
"CVE-2026-39821",
"CVE-2026-39822",
"CVE-2026-39823",
"CVE-2026-39824",
"CVE-2026-39825",
"CVE-2026-39826",
"CVE-2026-39827",
"CVE-2026-39828",
"CVE-2026-39829",
"CVE-2026-39830",
"CVE-2026-39831",
"CVE-2026-39832",
"CVE-2026-39833",
"CVE-2026-39834",
"CVE-2026-39835",
"CVE-2026-39836",
"CVE-2026-40097",
"CVE-2026-41178",
"CVE-2026-41889",
"CVE-2026-42499",
"CVE-2026-42502",
"CVE-2026-42504",
"CVE-2026-42505",
"CVE-2026-42506",
"CVE-2026-42507",
"CVE-2026-42508",
"CVE-2026-46595",
"CVE-2026-46597",
"CVE-2026-46598",
"CVE-2026-46600",
"CVE-2026-56852",
"CVE-2026-56853",
"CVE-2026-56854",
"CVE-2026-56855",
"CVE-2026-56858",
"CVE-2026-56859",
"CVE-2026-56860",
"CVE-2026-56862",
"CVE-2026-78662",
"CVE-2026-84304",
"ghsa-259r-337f-4rfw",
"ghsa-3fxj-6jh8-hvhx",
"ghsa-9g5q-2w5x-hmxf",
"ghsa-hrxh-6v49-42gf",
"ghsa-rjr7-jggh-pgcp"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-QK89502 (CVE-2025-47912)
Vulnerability from cleanstart – Published: 2026-09-10 01:06 – Updated: 2026-09-18 11:59 – Source websiteMultiple security vulnerabilities affect the vault-k8s package. The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. See references for individual vulnerability details.
| URL | Type | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "vault-k8s"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.7.4-r0"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"credits": [],
"database_specific": {},
"details": "Multiple security vulnerabilities affect the vault-k8s package. The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. See references for individual vulnerability details.",
"id": "CLEANSTART-2026-QK89502",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-09-10T01:06:07.433248Z",
"references": [
{
"type": "ADVISORY",
"url": "https://github.com/cleanstart-dev/cleanstart-security-advisories/tree/main/advisories/2026/CLEANSTART-2026-QK89502.json"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-47912"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-58183"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-58185"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-58186"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-58187"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-58188"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-58189"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-61723"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-61724"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-61725"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-61729"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-25680"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-25681"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-27136"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-33811"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-33814"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-33818"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39817"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39819"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39820"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39821"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39822"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39823"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39824"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39825"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39826"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39827"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39828"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39829"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39830"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39831"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39832"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39833"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39834"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39835"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39836"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42499"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42501"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42502"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42505"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42506"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42508"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-46595"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-46597"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-46598"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-46600"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56852"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56853"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56858"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56859"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56860"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56862"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-259r-337f-4rfw"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47912"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58183"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58185"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58186"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58187"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58188"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58189"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61723"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61724"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61725"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61729"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25680"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25681"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27136"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33811"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33814"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33818"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39817"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39819"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39820"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39821"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39822"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39823"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39824"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39825"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39826"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39827"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39828"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39829"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39830"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39831"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39832"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39833"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39834"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39835"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39836"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42499"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42501"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42502"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42505"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42506"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42508"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46595"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46597"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46598"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46600"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56852"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56853"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56858"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56859"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56860"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56862"
}
],
"related": [],
"schema_version": "1.7.3",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"type": "CVSS_V3"
}
],
"summary": "ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label",
"upstream": [
"CVE-2025-47912",
"CVE-2025-58183",
"CVE-2025-58185",
"CVE-2025-58186",
"CVE-2025-58187",
"CVE-2025-58188",
"CVE-2025-58189",
"CVE-2025-61723",
"CVE-2025-61724",
"CVE-2025-61725",
"CVE-2025-61729",
"CVE-2026-25680",
"CVE-2026-25681",
"CVE-2026-27136",
"CVE-2026-33811",
"CVE-2026-33814",
"CVE-2026-33818",
"CVE-2026-39817",
"CVE-2026-39819",
"CVE-2026-39820",
"CVE-2026-39821",
"CVE-2026-39822",
"CVE-2026-39823",
"CVE-2026-39824",
"CVE-2026-39825",
"CVE-2026-39826",
"CVE-2026-39827",
"CVE-2026-39828",
"CVE-2026-39829",
"CVE-2026-39830",
"CVE-2026-39831",
"CVE-2026-39832",
"CVE-2026-39833",
"CVE-2026-39834",
"CVE-2026-39835",
"CVE-2026-39836",
"CVE-2026-42499",
"CVE-2026-42501",
"CVE-2026-42502",
"CVE-2026-42505",
"CVE-2026-42506",
"CVE-2026-42508",
"CVE-2026-46595",
"CVE-2026-46597",
"CVE-2026-46598",
"CVE-2026-46600",
"CVE-2026-56852",
"CVE-2026-56853",
"CVE-2026-56858",
"CVE-2026-56859",
"CVE-2026-56860",
"CVE-2026-56862",
"ghsa-259r-337f-4rfw"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-QN07777 (CVE-2026-2303)
Vulnerability from cleanstart – Published: 2026-09-10 02:44 – Updated: 2026-09-18 11:59 – Source websiteMultiple security vulnerabilities affect the vault package. Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. See references for individual vulnerability details.
| URL | Type | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "vault"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "2.0.0-r1"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"credits": [],
"database_specific": {},
"details": "Multiple security vulnerabilities affect the vault package. Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. See references for individual vulnerability details.",
"id": "CLEANSTART-2026-QN07777",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-09-10T02:44:41.763845Z",
"references": [
{
"type": "ADVISORY",
"url": "https://github.com/cleanstart-dev/cleanstart-security-advisories/tree/main/advisories/2026/CLEANSTART-2026-QN07777.json"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-2303"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-25680"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-25681"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-27136"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-32280"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-32281"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-32282"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-32283"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-32288"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-32289"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-32952"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-33186"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-33810"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-33811"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-33814"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-33816"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-33818"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-34040"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-34986"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39817"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39819"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39820"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39821"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39822"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39823"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39824"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39825"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39826"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39827"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39828"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39829"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39830"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39831"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39832"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39833"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39834"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39835"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39836"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39883"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-41178"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-41568"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-41602"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42306"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42499"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42501"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42502"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42505"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42506"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42508"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-44503"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-46595"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-46597"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-46598"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-46600"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56852"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56853"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56855"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56858"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56859"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56860"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56862"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-73500"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-78662"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-84304"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-259r-337f-4rfw"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-7j59-v9qr-6fq9"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-hrxh-6v49-42gf"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-j88v-2chj-qfwx"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-mpwr-8vm7-h73f"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-p77j-4mvh-x3m3"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-pjcq-xvwq-hhpj"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-w67g-5rqw-f597"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-wf45-q9ch-q8gh"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-xmrv-pmrh-hhx2"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-2303"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25680"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25681"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27136"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32280"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32281"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32282"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32283"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32288"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32289"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32952"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33186"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33810"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33811"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33814"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33816"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33818"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-34040"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-34986"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39817"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39819"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39820"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39821"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39822"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39823"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39824"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39825"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39826"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39827"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39828"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39829"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39830"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39831"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39832"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39833"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39834"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39835"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39836"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39883"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41178"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41568"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41602"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42306"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42499"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42501"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42502"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42505"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42506"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42508"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-44503"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46595"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46597"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46598"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46600"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56852"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56853"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56855"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56858"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56859"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56860"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56862"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-73500"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78662"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84304"
}
],
"related": [],
"schema_version": "1.7.3",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"type": "CVSS_V3"
}
],
"summary": "Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection",
"upstream": [
"CVE-2026-2303",
"CVE-2026-25680",
"CVE-2026-25681",
"CVE-2026-27136",
"CVE-2026-32280",
"CVE-2026-32281",
"CVE-2026-32282",
"CVE-2026-32283",
"CVE-2026-32288",
"CVE-2026-32289",
"CVE-2026-32952",
"CVE-2026-33186",
"CVE-2026-33810",
"CVE-2026-33811",
"CVE-2026-33814",
"CVE-2026-33816",
"CVE-2026-33818",
"CVE-2026-34040",
"CVE-2026-34986",
"CVE-2026-39817",
"CVE-2026-39819",
"CVE-2026-39820",
"CVE-2026-39821",
"CVE-2026-39822",
"CVE-2026-39823",
"CVE-2026-39824",
"CVE-2026-39825",
"CVE-2026-39826",
"CVE-2026-39827",
"CVE-2026-39828",
"CVE-2026-39829",
"CVE-2026-39830",
"CVE-2026-39831",
"CVE-2026-39832",
"CVE-2026-39833",
"CVE-2026-39834",
"CVE-2026-39835",
"CVE-2026-39836",
"CVE-2026-39883",
"CVE-2026-41178",
"CVE-2026-41568",
"CVE-2026-41602",
"CVE-2026-42306",
"CVE-2026-42499",
"CVE-2026-42501",
"CVE-2026-42502",
"CVE-2026-42505",
"CVE-2026-42506",
"CVE-2026-42508",
"CVE-2026-44503",
"CVE-2026-46595",
"CVE-2026-46597",
"CVE-2026-46598",
"CVE-2026-46600",
"CVE-2026-56852",
"CVE-2026-56853",
"CVE-2026-56855",
"CVE-2026-56858",
"CVE-2026-56859",
"CVE-2026-56860",
"CVE-2026-56862",
"CVE-2026-73500",
"CVE-2026-78662",
"CVE-2026-84304",
"ghsa-259r-337f-4rfw",
"ghsa-7j59-v9qr-6fq9",
"ghsa-hrxh-6v49-42gf",
"ghsa-j88v-2chj-qfwx",
"ghsa-mpwr-8vm7-h73f",
"ghsa-p77j-4mvh-x3m3",
"ghsa-pjcq-xvwq-hhpj",
"ghsa-w67g-5rqw-f597",
"ghsa-wf45-q9ch-q8gh",
"ghsa-xmrv-pmrh-hhx2"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-QN49433 (CVE-2026-14362)
Vulnerability from cleanstart – Published: 2026-09-08 00:44 – Updated: 2026-09-18 11:59 – Source websiteMultiple security vulnerabilities affect the weaviate-fips package. HashiCorp memberlist before version 0. See references for individual vulnerability details.
| URL | Type | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "weaviate-fips"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.37.14-r0"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"credits": [],
"database_specific": {},
"details": "Multiple security vulnerabilities affect the weaviate-fips package. HashiCorp memberlist before version 0. See references for individual vulnerability details.",
"id": "CLEANSTART-2026-QN49433",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-09-08T00:44:14.388523Z",
"references": [
{
"type": "ADVISORY",
"url": "https://github.com/cleanstart-dev/cleanstart-security-advisories/tree/main/advisories/2026/CLEANSTART-2026-QN49433.json"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-14362"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-2303"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-33811"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-33814"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39817"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39819"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39820"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39823"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39825"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39826"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39836"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42499"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42501"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-259r-337f-4rfw"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-xmrv-pmrh-hhx2"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-14362"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-2303"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33811"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33814"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39817"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39819"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39820"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39823"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39825"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39826"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39836"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42499"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42501"
}
],
"related": [],
"schema_version": "1.7.3",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"type": "CVSS_V3"
}
],
"summary": "HashiCorp memberlist before version 0",
"upstream": [
"CVE-2026-14362",
"CVE-2026-2303",
"CVE-2026-33811",
"CVE-2026-33814",
"CVE-2026-39817",
"CVE-2026-39819",
"CVE-2026-39820",
"CVE-2026-39823",
"CVE-2026-39825",
"CVE-2026-39826",
"CVE-2026-39836",
"CVE-2026-42499",
"CVE-2026-42501",
"ghsa-259r-337f-4rfw",
"ghsa-xmrv-pmrh-hhx2"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-QO69280 (CVE-2026-46600)
Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source websitePackage tempo version 2.9.5-r1 fixes 2 vulnerabilities: CVE-2026-46600, ghsa-259r-337f-4rfw
| URL | Type | |
|---|---|---|
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "tempo"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "2.9.5-r1"
}
],
"type": "ECOSYSTEM"
}
],
"versions": [
"2.9.5-r1"
]
}
],
"credits": [],
"database_specific": {},
"details": "Package tempo version 2.9.5-r1 fixes 2 vulnerabilities: CVE-2026-46600, ghsa-259r-337f-4rfw",
"id": "CLEANSTART-2026-QO69280",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-09-01T11:17:16Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/grafana/tempo"
}
],
"related": [],
"schema_version": "1.7.3",
"summary": "Security fixes in tempo 2.9.5-r1",
"upstream": [
"CVE-2026-46600",
"ghsa-259r-337f-4rfw"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-RC17482 (CVE-2025-15558)
Vulnerability from cleanstart – Published: 2026-09-10 03:06 – Updated: 2026-09-18 11:59 – Source websiteMultiple security vulnerabilities affect the minio-operator package. The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. See references for individual vulnerability details.
| URL | Type | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "minio-operator"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "7.1.1-r5"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"credits": [],
"database_specific": {},
"details": "Multiple security vulnerabilities affect the minio-operator package. The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. See references for individual vulnerability details.",
"id": "CLEANSTART-2026-RC17482",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-09-10T03:06:12.110499Z",
"references": [
{
"type": "ADVISORY",
"url": "https://github.com/cleanstart-dev/cleanstart-security-advisories/tree/main/advisories/2026/CLEANSTART-2026-RC17482.json"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-15558"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-22868"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-30204"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-47912"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-58183"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-58185"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-58186"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-58187"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-58188"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-58189"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-61723"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-61724"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-61725"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-61726"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-61727"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-61728"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-61729"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-61730"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-61731"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-61732"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-68119"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-68121"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-25679"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-25680"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-27139"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-27142"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-27145"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-33814"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-33818"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39821"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39822"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39833"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39836"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42499"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42504"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42505"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42507"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42508"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-46595"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-46600"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56852"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56853"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56858"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56859"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56860"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56862"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56864"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56865"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-259r-337f-4rfw"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-6v2p-p543-phr9"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-f6x5-jh6r-wrfv"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-j5w8-q4qc-rx2x"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-p436-gjf2-799p"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-15558"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22868"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30204"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47912"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58183"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58185"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58186"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58187"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58188"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58189"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61723"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61724"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61725"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61726"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61727"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61728"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61729"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61730"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61731"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61732"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-68119"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-68121"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25679"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25680"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27139"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27142"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27145"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33814"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33818"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39821"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39822"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39833"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39836"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42499"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42504"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42505"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42507"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42508"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46595"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46600"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56852"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56853"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56858"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56859"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56860"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56862"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56864"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56865"
}
],
"related": [],
"schema_version": "1.7.3",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"type": "CVSS_V3"
}
],
"summary": "ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label",
"upstream": [
"CVE-2025-15558",
"CVE-2025-22868",
"CVE-2025-30204",
"CVE-2025-47912",
"CVE-2025-58183",
"CVE-2025-58185",
"CVE-2025-58186",
"CVE-2025-58187",
"CVE-2025-58188",
"CVE-2025-58189",
"CVE-2025-61723",
"CVE-2025-61724",
"CVE-2025-61725",
"CVE-2025-61726",
"CVE-2025-61727",
"CVE-2025-61728",
"CVE-2025-61729",
"CVE-2025-61730",
"CVE-2025-61731",
"CVE-2025-61732",
"CVE-2025-68119",
"CVE-2025-68121",
"CVE-2026-25679",
"CVE-2026-25680",
"CVE-2026-27139",
"CVE-2026-27142",
"CVE-2026-27145",
"CVE-2026-33814",
"CVE-2026-33818",
"CVE-2026-39821",
"CVE-2026-39822",
"CVE-2026-39833",
"CVE-2026-39836",
"CVE-2026-42499",
"CVE-2026-42504",
"CVE-2026-42505",
"CVE-2026-42507",
"CVE-2026-42508",
"CVE-2026-46595",
"CVE-2026-46600",
"CVE-2026-56852",
"CVE-2026-56853",
"CVE-2026-56858",
"CVE-2026-56859",
"CVE-2026-56860",
"CVE-2026-56862",
"CVE-2026-56864",
"CVE-2026-56865",
"ghsa-259r-337f-4rfw",
"ghsa-6v2p-p543-phr9",
"ghsa-f6x5-jh6r-wrfv",
"ghsa-j5w8-q4qc-rx2x",
"ghsa-p436-gjf2-799p"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-RH24736 (GHSA-R277-6W6Q-XMQW)
Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source websitePackage grafana version 12.4.9-r1 fixes 9 vulnerabilities: ghsa-r277-6w6q-xmqw, CVE-2026-73502, CVE-2026-42151, CVE-2026-44903, CVE-2026-21728...
| URL | Type | |
|---|---|---|
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "grafana"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "12.4.9-r1"
}
],
"type": "ECOSYSTEM"
}
],
"versions": [
"12.4.9-r1"
]
}
],
"credits": [],
"database_specific": {},
"details": "Package grafana version 12.4.9-r1 fixes 9 vulnerabilities: ghsa-r277-6w6q-xmqw, CVE-2026-73502, CVE-2026-42151, CVE-2026-44903, CVE-2026-21728...",
"id": "CLEANSTART-2026-RH24736",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-09-01T11:17:16Z",
"references": [
{
"type": "WEB",
"url": "https://grafana.com"
}
],
"related": [],
"schema_version": "1.7.3",
"summary": "Security fixes in grafana 12.4.9-r1",
"upstream": [
"ghsa-r277-6w6q-xmqw",
"CVE-2026-73502",
"CVE-2026-42151",
"CVE-2026-44903",
"CVE-2026-21728",
"CVE-2026-28377",
"ghsa-gcjh-h69q-9w9g",
"CVE-2026-2303",
"ghsa-259r-337f-4rfw"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-RM95899 (GHSA-HRXH-6V49-42GF)
Vulnerability from cleanstart – Published: 2026-08-13 12:10 – Updated: 2026-09-18 11:59 – Source websitePackage cortex version 1.18.1-r4 fixes 3 vulnerabilities: ghsa-hrxh-6v49-42gf, ghsa-259r-337f-4rfw, CVE-2026-41178
| URL | Type | |
|---|---|---|
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "cortex"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.18.1-r4"
}
],
"type": "ECOSYSTEM"
}
],
"versions": [
"1.18.1-r4"
]
}
],
"credits": [],
"database_specific": {},
"details": "Package cortex version 1.18.1-r4 fixes 3 vulnerabilities: ghsa-hrxh-6v49-42gf, ghsa-259r-337f-4rfw, CVE-2026-41178",
"id": "CLEANSTART-2026-RM95899",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-08-13T12:10:09Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/cortexproject/cortex"
}
],
"related": [],
"schema_version": "1.7.3",
"summary": "Security fixes in cortex 1.18.1-r4",
"upstream": [
"ghsa-hrxh-6v49-42gf",
"ghsa-259r-337f-4rfw",
"CVE-2026-41178"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-RU71621 (GHSA-R277-6W6Q-XMQW)
Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source websitePackage grafana version 12.4.7-r1 fixes 10 vulnerabilities: ghsa-r277-6w6q-xmqw, ghsa-jpcw-4wr7-c3vq, ghsa-gcjh-h69q-9w9g, CVE-2026-21728, CVE-2026-28377...
| URL | Type | |
|---|---|---|
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "grafana"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "12.4.7-r1"
}
],
"type": "ECOSYSTEM"
}
],
"versions": [
"12.4.7-r1"
]
}
],
"credits": [],
"database_specific": {},
"details": "Package grafana version 12.4.7-r1 fixes 10 vulnerabilities: ghsa-r277-6w6q-xmqw, ghsa-jpcw-4wr7-c3vq, ghsa-gcjh-h69q-9w9g, CVE-2026-21728, CVE-2026-28377...",
"id": "CLEANSTART-2026-RU71621",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-09-01T11:17:16Z",
"references": [
{
"type": "WEB",
"url": "https://grafana.com"
}
],
"related": [],
"schema_version": "1.7.3",
"summary": "Security fixes in grafana 12.4.7-r1",
"upstream": [
"ghsa-r277-6w6q-xmqw",
"ghsa-jpcw-4wr7-c3vq",
"ghsa-gcjh-h69q-9w9g",
"CVE-2026-21728",
"CVE-2026-28377",
"CVE-2026-42151",
"CVE-2026-40179",
"CVE-2026-44903",
"CVE-2026-2303",
"ghsa-259r-337f-4rfw"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-SA31637 (CVE-2026-41178)
Vulnerability from cleanstart – Published: 2026-08-13 12:10 – Updated: 2026-09-18 11:59 – Source websitePackage knative-net-istio version 1.21.4-r2 fixes 2 vulnerabilities: CVE-2026-41178, ghsa-259r-337f-4rfw
| URL | Type | |
|---|---|---|
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "knative-net-istio"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.21.4-r2"
}
],
"type": "ECOSYSTEM"
}
],
"versions": [
"1.21.4-r2"
]
}
],
"credits": [],
"database_specific": {},
"details": "Package knative-net-istio version 1.21.4-r2 fixes 2 vulnerabilities: CVE-2026-41178, ghsa-259r-337f-4rfw",
"id": "CLEANSTART-2026-SA31637",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-08-13T12:10:09Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/knative-extensions/net-istio"
}
],
"related": [],
"schema_version": "1.7.3",
"summary": "Security fixes in knative-net-istio 1.21.4-r2",
"upstream": [
"CVE-2026-41178",
"ghsa-259r-337f-4rfw"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-SB31025 (CVE-2026-56860)
Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source websitePackage prometheus-fips version 3.11.3-r1 fixes 17 vulnerabilities: CVE-2026-56860, CVE-2026-56858, CVE-2026-33818, CVE-2026-46600, CVE-2026-56853...
| URL | Type | |
|---|---|---|
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "prometheus-fips"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "3.11.3-r1"
}
],
"type": "ECOSYSTEM"
}
],
"versions": [
"3.11.3-r1"
]
}
],
"credits": [],
"database_specific": {},
"details": "Package prometheus-fips version 3.11.3-r1 fixes 17 vulnerabilities: CVE-2026-56860, CVE-2026-56858, CVE-2026-33818, CVE-2026-46600, CVE-2026-56853...",
"id": "CLEANSTART-2026-SB31025",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-09-01T11:17:16Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/prometheus/prometheus"
}
],
"related": [],
"schema_version": "1.7.3",
"summary": "Security fixes in prometheus-fips 3.11.3-r1",
"upstream": [
"CVE-2026-56860",
"CVE-2026-56858",
"CVE-2026-33818",
"CVE-2026-46600",
"CVE-2026-56853",
"CVE-2026-56859",
"CVE-2026-56862",
"CVE-2026-39821",
"CVE-2026-33997",
"CVE-2026-41567",
"CVE-2026-42306",
"CVE-2026-34040",
"CVE-2026-41568",
"ghsa-hrxh-6v49-42gf",
"CVE-2026-2303",
"CVE-2026-41178",
"ghsa-259r-337f-4rfw"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-SC87229 (GHSA-HRXH-6V49-42GF)
Vulnerability from cleanstart – Published: 2026-07-30 07:10 – Updated: 2026-09-18 11:59 – Source websitePackage rclone version 1.73.5-r5 fixes 5 vulnerabilities: ghsa-hrxh-6v49-42gf, ghsa-259r-337f-4rfw, ghsa-3fxj-6jh8-hvhx, ghsa-9g5q-2w5x-hmxf, ghsa-rjr7-jggh-pgcp
| URL | Type | |
|---|---|---|
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "rclone"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.73.5-r5"
}
],
"type": "ECOSYSTEM"
}
],
"versions": [
"1.73.5-r5"
]
}
],
"credits": [],
"database_specific": {},
"details": "Package rclone version 1.73.5-r5 fixes 5 vulnerabilities: ghsa-hrxh-6v49-42gf, ghsa-259r-337f-4rfw, ghsa-3fxj-6jh8-hvhx, ghsa-9g5q-2w5x-hmxf, ghsa-rjr7-jggh-pgcp",
"id": "CLEANSTART-2026-SC87229",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-07-30T07:10:53Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/rclone/rclone"
}
],
"related": [],
"schema_version": "1.7.3",
"summary": "Security fixes in rclone 1.73.5-r5",
"upstream": [
"ghsa-hrxh-6v49-42gf",
"ghsa-259r-337f-4rfw",
"ghsa-3fxj-6jh8-hvhx",
"ghsa-9g5q-2w5x-hmxf",
"ghsa-rjr7-jggh-pgcp"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-SH16039 (GHSA-259R-337F-4RFW)
Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source websitePackage ollama-fips version 0.32.8-r1 fixes 1 vulnerabilities: ghsa-259r-337f-4rfw
| URL | Type | |
|---|---|---|
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "ollama-fips"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.32.8-r1"
}
],
"type": "ECOSYSTEM"
}
],
"versions": [
"0.32.8-r1"
]
}
],
"credits": [],
"database_specific": {},
"details": "Package ollama-fips version 0.32.8-r1 fixes 1 vulnerabilities: ghsa-259r-337f-4rfw",
"id": "CLEANSTART-2026-SH16039",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-09-01T11:17:16Z",
"references": [
{
"type": "WEB",
"url": "https://ollama.com"
}
],
"related": [],
"schema_version": "1.7.3",
"summary": "Security fixes in ollama-fips 0.32.8-r1",
"upstream": [
"ghsa-259r-337f-4rfw"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-SK52724 (CVE-2026-54787)
Vulnerability from cleanstart – Published: 2026-08-13 12:10 – Updated: 2026-09-18 11:59 – Source websitePackage cosign version 3.1.2-r1 fixes 9 vulnerabilities: CVE-2026-54787, ghsa-hrxh-6v49-42gf, ghsa-259r-337f-4rfw, CVE-2026-49835, ghsa-9c54-x2g4-v92j...
| URL | Type | |
|---|---|---|
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "cosign"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "3.1.2-r1"
}
],
"type": "ECOSYSTEM"
}
],
"versions": [
"3.1.2-r1"
]
}
],
"credits": [],
"database_specific": {},
"details": "Package cosign version 3.1.2-r1 fixes 9 vulnerabilities: CVE-2026-54787, ghsa-hrxh-6v49-42gf, ghsa-259r-337f-4rfw, CVE-2026-49835, ghsa-9c54-x2g4-v92j...",
"id": "CLEANSTART-2026-SK52724",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-08-13T12:10:09Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/sigstore/cosign"
}
],
"related": [],
"schema_version": "1.7.3",
"summary": "Security fixes in cosign 3.1.2-r1",
"upstream": [
"CVE-2026-54787",
"ghsa-hrxh-6v49-42gf",
"ghsa-259r-337f-4rfw",
"CVE-2026-49835",
"ghsa-9c54-x2g4-v92j",
"CVE-2026-49834",
"ghsa-9vcr-p3rj-q5q6",
"CVE-2026-48702",
"ghsa-47q9-m4ww-924m"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-SL17084 (CVE-2026-33186)
Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source websitePackage step-ca version 0.27.5-r0 fixes 14 vulnerabilities: CVE-2026-33186, CVE-2025-27144, CVE-2026-34986, CVE-2025-22868, CVE-2026-25793...
| URL | Type | |
|---|---|---|
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "step-ca"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.27.5-r0"
}
],
"type": "ECOSYSTEM"
}
],
"versions": [
"0.27.5-r0"
]
}
],
"credits": [],
"database_specific": {},
"details": "Package step-ca version 0.27.5-r0 fixes 14 vulnerabilities: CVE-2026-33186, CVE-2025-27144, CVE-2026-34986, CVE-2025-22868, CVE-2026-25793...",
"id": "CLEANSTART-2026-SL17084",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-09-01T11:17:16Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/smallstep/certificates"
}
],
"related": [],
"schema_version": "1.7.3",
"summary": "Security fixes in step-ca 0.27.5-r0",
"upstream": [
"CVE-2026-33186",
"CVE-2025-27144",
"CVE-2026-34986",
"CVE-2025-22868",
"CVE-2026-25793",
"CVE-2025-62820",
"CVE-2024-45339",
"CVE-2026-26958",
"CVE-2025-30204",
"ghsa-vrw8-fxc6-2r93",
"ghsa-9g5q-2w5x-hmxf",
"ghsa-rjr7-jggh-pgcp",
"ghsa-259r-337f-4rfw",
"ghsa-hrxh-6v49-42gf"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-SP46945 (CVE-2026-39828)
Vulnerability from cleanstart – Published: 2026-08-13 12:10 – Updated: 2026-09-18 11:59 – Source websitePackage percona-server-mongodb-operator version 1.23.0-r0 fixes 22 vulnerabilities: CVE-2026-39828, CVE-2026-39829, CVE-2026-39830, CVE-2026-39831, CVE-2026-39832...
| URL | Type | |
|---|---|---|
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "percona-server-mongodb-operator"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.23.0-r0"
}
],
"type": "ECOSYSTEM"
}
],
"versions": [
"1.23.0-r0"
]
}
],
"credits": [],
"database_specific": {},
"details": "Package percona-server-mongodb-operator version 1.23.0-r0 fixes 22 vulnerabilities: CVE-2026-39828, CVE-2026-39829, CVE-2026-39830, CVE-2026-39831, CVE-2026-39832...",
"id": "CLEANSTART-2026-SP46945",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-08-13T12:10:09Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/percona/percona-server-mongodb-operator.git"
}
],
"related": [],
"schema_version": "1.7.3",
"summary": "Security fixes in percona-server-mongodb-operator 1.23.0-r0",
"upstream": [
"CVE-2026-39828",
"CVE-2026-39829",
"CVE-2026-39830",
"CVE-2026-39831",
"CVE-2026-39832",
"CVE-2026-39835",
"CVE-2026-42508",
"CVE-2026-46595",
"CVE-2026-46597",
"CVE-2026-39827",
"CVE-2026-39833",
"CVE-2026-39834",
"CVE-2026-46598",
"CVE-2026-25681",
"CVE-2026-27136",
"CVE-2026-39821",
"CVE-2026-25680",
"CVE-2026-42502",
"CVE-2026-42506",
"CVE-2026-46600",
"CVE-2026-56852",
"ghsa-259r-337f-4rfw"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-SS10950 (CVE-2026-46603)
Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source websitePackage gitea version 1.27.2-r1 fixes 9 vulnerabilities: CVE-2026-46603, CVE-2026-56864, CVE-2026-56865, CVE-2026-71556, CVE-2026-71557...
| URL | Type | |
|---|---|---|
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "gitea"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.27.2-r1"
}
],
"type": "ECOSYSTEM"
}
],
"versions": [
"1.27.2-r1"
]
}
],
"credits": [],
"database_specific": {},
"details": "Package gitea version 1.27.2-r1 fixes 9 vulnerabilities: CVE-2026-46603, CVE-2026-56864, CVE-2026-56865, CVE-2026-71556, CVE-2026-71557...",
"id": "CLEANSTART-2026-SS10950",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-09-01T11:17:16Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/go-gitea/gitea"
}
],
"related": [],
"schema_version": "1.7.3",
"summary": "Security fixes in gitea 1.27.2-r1",
"upstream": [
"CVE-2026-46603",
"CVE-2026-56864",
"CVE-2026-56865",
"CVE-2026-71556",
"CVE-2026-71557",
"ghsa-259r-337f-4rfw",
"ghsa-3fxj-6jh8-hvhx",
"ghsa-9g5q-2w5x-hmxf",
"ghsa-rjr7-jggh-pgcg"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-SU87029 (GHSA-259R-337F-4RFW)
Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source websitePackage argo-cd version 3.3.12-r4 fixes 2 vulnerabilities: ghsa-259r-337f-4rfw, CVE-2026-41178
| URL | Type | |
|---|---|---|
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "argo-cd"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "3.3.12-r4"
}
],
"type": "ECOSYSTEM"
}
],
"versions": [
"3.3.12-r4"
]
}
],
"credits": [],
"database_specific": {},
"details": "Package argo-cd version 3.3.12-r4 fixes 2 vulnerabilities: ghsa-259r-337f-4rfw, CVE-2026-41178",
"id": "CLEANSTART-2026-SU87029",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-09-01T11:17:16Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/argoproj/argo-cd"
}
],
"related": [],
"schema_version": "1.7.3",
"summary": "Security fixes in argo-cd 3.3.12-r4",
"upstream": [
"ghsa-259r-337f-4rfw",
"CVE-2026-41178"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-TD50332 (CVE-2026-56860)
Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source websitePackage local-path-provisioner-fips version 0.0.36-r1 fixes 19 vulnerabilities: CVE-2026-56860, CVE-2026-56858, CVE-2026-33818, CVE-2026-56853, CVE-2026-56859...
| URL | Type | |
|---|---|---|
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "local-path-provisioner-fips"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.0.36-r1"
}
],
"type": "ECOSYSTEM"
}
],
"versions": [
"0.0.36-r1"
]
}
],
"credits": [],
"database_specific": {},
"details": "Package local-path-provisioner-fips version 0.0.36-r1 fixes 19 vulnerabilities: CVE-2026-56860, CVE-2026-56858, CVE-2026-33818, CVE-2026-56853, CVE-2026-56859...",
"id": "CLEANSTART-2026-TD50332",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-09-01T11:17:16Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/rancher/local-path-provisioner"
}
],
"related": [],
"schema_version": "1.7.3",
"summary": "Security fixes in local-path-provisioner-fips 0.0.36-r1",
"upstream": [
"CVE-2026-56860",
"CVE-2026-56858",
"CVE-2026-33818",
"CVE-2026-56853",
"CVE-2026-56859",
"CVE-2026-56862",
"CVE-2026-46600",
"CVE-2026-25681",
"CVE-2026-27136",
"CVE-2026-33814",
"CVE-2026-39821",
"CVE-2025-47911",
"CVE-2025-58190",
"CVE-2026-42502",
"CVE-2026-42506",
"CVE-2026-25680",
"CVE-2026-39824",
"CVE-2026-56852",
"ghsa-259r-337f-4rfw"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-TJ10436 (GHSA-259R-337F-4RFW)
Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source websitePackage ollama version 0.31.2-r1 fixes 1 vulnerabilities: ghsa-259r-337f-4rfw
| URL | Type | |
|---|---|---|
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "ollama"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.31.2-r1"
}
],
"type": "ECOSYSTEM"
}
],
"versions": [
"0.31.2-r1"
]
}
],
"credits": [],
"database_specific": {},
"details": "Package ollama version 0.31.2-r1 fixes 1 vulnerabilities: ghsa-259r-337f-4rfw",
"id": "CLEANSTART-2026-TJ10436",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-09-01T11:17:16Z",
"references": [
{
"type": "WEB",
"url": "https://ollama.com"
}
],
"related": [],
"schema_version": "1.7.3",
"summary": "Security fixes in ollama 0.31.2-r1",
"upstream": [
"ghsa-259r-337f-4rfw"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-TO35695 (CVE-2026-24051)
Vulnerability from cleanstart – Published: 2026-09-16 01:06 – Updated: 2026-09-18 11:59 – Source websiteMultiple security vulnerabilities affect the cert-manager package. Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. See references for individual vulnerability details.
| URL | Type | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "cert-manager"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.19.2-r0"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"credits": [],
"database_specific": {},
"details": "Multiple security vulnerabilities affect the cert-manager package. Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. See references for individual vulnerability details.",
"id": "CLEANSTART-2026-TO35695",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-09-16T01:06:44.709827Z",
"references": [
{
"type": "ADVISORY",
"url": "https://github.com/cleanstart-dev/cleanstart-security-advisories/tree/main/advisories/2026/CLEANSTART-2026-TO35695.json"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-24051"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-25680"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-25681"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-27136"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-27145"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-32952"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-33186"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-33811"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-33814"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-33818"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-34986"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39820"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39821"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39822"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39823"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39824"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39825"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39826"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39827"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39828"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39829"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39830"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39831"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39832"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39833"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39834"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39835"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39836"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39883"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-41178"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42499"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42502"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42504"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42505"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42506"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42507"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42508"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-46595"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-46597"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-46598"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-46600"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56852"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56853"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56855"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56858"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56859"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56860"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56862"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-73500"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-78662"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-84303"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-84304"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-84445"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-259r-337f-4rfw"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-78h2-9frx-2jm8"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-9h8m-3fm2-qjrq"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-gcjh-h69q-9w9g"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-hrxh-6v49-42gf"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-p77j-4mvh-x3m3"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-24051"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25680"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25681"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27136"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27145"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32952"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33186"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33811"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33814"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33818"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-34986"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39820"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39821"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39822"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39823"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39824"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39825"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39826"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39827"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39828"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39829"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39830"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39831"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39832"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39833"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39834"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39835"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39836"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39883"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41178"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42499"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42502"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42504"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42505"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42506"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42507"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42508"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46595"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46597"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46598"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46600"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56852"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56853"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56855"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56858"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56859"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56860"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56862"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-73500"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78662"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84303"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84304"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84445"
}
],
"related": [],
"schema_version": "1.7.3",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"type": "CVSS_V3"
}
],
"summary": "Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection",
"upstream": [
"CVE-2026-24051",
"CVE-2026-25680",
"CVE-2026-25681",
"CVE-2026-27136",
"CVE-2026-27145",
"CVE-2026-32952",
"CVE-2026-33186",
"CVE-2026-33811",
"CVE-2026-33814",
"CVE-2026-33818",
"CVE-2026-34986",
"CVE-2026-39820",
"CVE-2026-39821",
"CVE-2026-39822",
"CVE-2026-39823",
"CVE-2026-39824",
"CVE-2026-39825",
"CVE-2026-39826",
"CVE-2026-39827",
"CVE-2026-39828",
"CVE-2026-39829",
"CVE-2026-39830",
"CVE-2026-39831",
"CVE-2026-39832",
"CVE-2026-39833",
"CVE-2026-39834",
"CVE-2026-39835",
"CVE-2026-39836",
"CVE-2026-39883",
"CVE-2026-41178",
"CVE-2026-42499",
"CVE-2026-42502",
"CVE-2026-42504",
"CVE-2026-42505",
"CVE-2026-42506",
"CVE-2026-42507",
"CVE-2026-42508",
"CVE-2026-46595",
"CVE-2026-46597",
"CVE-2026-46598",
"CVE-2026-46600",
"CVE-2026-56852",
"CVE-2026-56853",
"CVE-2026-56855",
"CVE-2026-56858",
"CVE-2026-56859",
"CVE-2026-56860",
"CVE-2026-56862",
"CVE-2026-73500",
"CVE-2026-78662",
"CVE-2026-84303",
"CVE-2026-84304",
"CVE-2026-84445",
"ghsa-259r-337f-4rfw",
"ghsa-78h2-9frx-2jm8",
"ghsa-9h8m-3fm2-qjrq",
"ghsa-gcjh-h69q-9w9g",
"ghsa-hrxh-6v49-42gf",
"ghsa-p77j-4mvh-x3m3"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-TR82670 (GHSA-259R-337F-4RFW)
Vulnerability from cleanstart – Published: 2026-07-30 07:10 – Updated: 2026-09-18 11:59 – Source websitePackage prometheus-redis-exporter version 1.87.0-r0 fixes 1 vulnerabilities: ghsa-259r-337f-4rfw
| URL | Type | |
|---|---|---|
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "prometheus-redis-exporter"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.87.0-r0"
}
],
"type": "ECOSYSTEM"
}
],
"versions": [
"1.87.0-r0"
]
}
],
"credits": [],
"database_specific": {},
"details": "Package prometheus-redis-exporter version 1.87.0-r0 fixes 1 vulnerabilities: ghsa-259r-337f-4rfw",
"id": "CLEANSTART-2026-TR82670",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-07-30T07:10:53Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/oliver006/redis_exporter"
}
],
"related": [],
"schema_version": "1.7.3",
"summary": "Security fixes in prometheus-redis-exporter 1.87.0-r0",
"upstream": [
"ghsa-259r-337f-4rfw"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-TX42489 (GHSA-HRXH-6V49-42GF)
Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source websitePackage pulumi version 3.248.0-r0 fixes 30 vulnerabilities: ghsa-hrxh-6v49-42gf, CVE-2026-56864, CVE-2026-56865, CVE-2026-56852, CVE-2026-71556...
| URL | Type | |
|---|---|---|
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "pulumi"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "3.248.0-r0"
}
],
"type": "ECOSYSTEM"
}
],
"versions": [
"3.248.0-r0"
]
}
],
"credits": [],
"database_specific": {},
"details": "Package pulumi version 3.248.0-r0 fixes 30 vulnerabilities: ghsa-hrxh-6v49-42gf, CVE-2026-56864, CVE-2026-56865, CVE-2026-56852, CVE-2026-71556...",
"id": "CLEANSTART-2026-TX42489",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-09-01T11:17:16Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/pulumi/pulumi"
}
],
"related": [],
"schema_version": "1.7.3",
"summary": "Security fixes in pulumi 3.248.0-r0",
"upstream": [
"ghsa-hrxh-6v49-42gf",
"CVE-2026-56864",
"CVE-2026-56865",
"CVE-2026-56852",
"CVE-2026-71556",
"CVE-2026-71557",
"ghsa-259r-337f-4rfw",
"CVE-2026-5160",
"CVE-2026-59873",
"CVE-2026-59871",
"CVE-2026-59874",
"CVE-2026-59875",
"CVE-2026-53655",
"ghsa-r292-9mhp-454m",
"CVE-2026-59869",
"ghsa-5p4m-2wfm-xmqj",
"CVE-2026-45149",
"CVE-2026-14257",
"CVE-2026-69152",
"CVE-2026-13149",
"CVE-2026-54285",
"CVE-2026-59892",
"CVE-2026-59877",
"CVE-2026-9496",
"CVE-2026-9358",
"CVE-2026-69192",
"CVE-2026-42338",
"CVE-2026-48758",
"CVE-2026-48815",
"CVE-2026-48816"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-TY53144 (CVE-2026-2303)
Vulnerability from cleanstart – Published: 2026-09-10 02:43 – Updated: 2026-09-18 11:59 – Source websiteMultiple security vulnerabilities affect the vault package. Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. See references for individual vulnerability details.
| URL | Type | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "vault"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.21.4-r9"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"credits": [],
"database_specific": {},
"details": "Multiple security vulnerabilities affect the vault package. Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. See references for individual vulnerability details.",
"id": "CLEANSTART-2026-TY53144",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-09-10T02:43:42.648597Z",
"references": [
{
"type": "ADVISORY",
"url": "https://github.com/cleanstart-dev/cleanstart-security-advisories/tree/main/advisories/2026/CLEANSTART-2026-TY53144.json"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-2303"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-25680"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-25681"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-27136"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-27145"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-32280"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-32281"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-32282"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-32283"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-32288"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-32289"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-32952"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-33186"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-33810"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-33811"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-33814"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-33816"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-33818"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-34040"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-34986"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39817"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39819"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39820"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39821"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39822"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39823"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39824"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39825"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39826"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39827"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39828"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39829"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39830"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39831"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39832"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39833"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39834"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39835"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39836"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39883"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-41178"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-41602"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-41889"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42499"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42501"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42502"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42504"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42505"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42506"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42507"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42508"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-43871"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-44503"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-46595"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-46597"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-46598"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-46600"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56852"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56853"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56855"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56858"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56859"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56860"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56862"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-73500"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-78662"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-84304"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-259r-337f-4rfw"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-7j59-v9qr-6fq9"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-cp6g-7hqx-qxhp"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-hrxh-6v49-42gf"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-j88v-2chj-qfwx"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-p77j-4mvh-x3m3"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-pjcq-xvwq-hhpj"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-wf45-q9ch-q8gh"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-xmrv-pmrh-hhx2"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-2303"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25680"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25681"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27136"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27145"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32280"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32281"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32282"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32283"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32288"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32289"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32952"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33186"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33810"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33811"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33814"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33816"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33818"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-34040"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-34986"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39817"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39819"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39820"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39821"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39822"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39823"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39824"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39825"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39826"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39827"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39828"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39829"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39830"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39831"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39832"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39833"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39834"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39835"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39836"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39883"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41178"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41602"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41889"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42499"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42501"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42502"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42504"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42505"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42506"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42507"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42508"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-43871"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-44503"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46595"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46597"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46598"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46600"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56852"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56853"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56855"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56858"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56859"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56860"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56862"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-73500"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78662"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84304"
}
],
"related": [],
"schema_version": "1.7.3",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"type": "CVSS_V3"
}
],
"summary": "Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection",
"upstream": [
"CVE-2026-2303",
"CVE-2026-25680",
"CVE-2026-25681",
"CVE-2026-27136",
"CVE-2026-27145",
"CVE-2026-32280",
"CVE-2026-32281",
"CVE-2026-32282",
"CVE-2026-32283",
"CVE-2026-32288",
"CVE-2026-32289",
"CVE-2026-32952",
"CVE-2026-33186",
"CVE-2026-33810",
"CVE-2026-33811",
"CVE-2026-33814",
"CVE-2026-33816",
"CVE-2026-33818",
"CVE-2026-34040",
"CVE-2026-34986",
"CVE-2026-39817",
"CVE-2026-39819",
"CVE-2026-39820",
"CVE-2026-39821",
"CVE-2026-39822",
"CVE-2026-39823",
"CVE-2026-39824",
"CVE-2026-39825",
"CVE-2026-39826",
"CVE-2026-39827",
"CVE-2026-39828",
"CVE-2026-39829",
"CVE-2026-39830",
"CVE-2026-39831",
"CVE-2026-39832",
"CVE-2026-39833",
"CVE-2026-39834",
"CVE-2026-39835",
"CVE-2026-39836",
"CVE-2026-39883",
"CVE-2026-41178",
"CVE-2026-41602",
"CVE-2026-41889",
"CVE-2026-42499",
"CVE-2026-42501",
"CVE-2026-42502",
"CVE-2026-42504",
"CVE-2026-42505",
"CVE-2026-42506",
"CVE-2026-42507",
"CVE-2026-42508",
"CVE-2026-43871",
"CVE-2026-44503",
"CVE-2026-46595",
"CVE-2026-46597",
"CVE-2026-46598",
"CVE-2026-46600",
"CVE-2026-56852",
"CVE-2026-56853",
"CVE-2026-56855",
"CVE-2026-56858",
"CVE-2026-56859",
"CVE-2026-56860",
"CVE-2026-56862",
"CVE-2026-73500",
"CVE-2026-78662",
"CVE-2026-84304",
"ghsa-259r-337f-4rfw",
"ghsa-7j59-v9qr-6fq9",
"ghsa-cp6g-7hqx-qxhp",
"ghsa-hrxh-6v49-42gf",
"ghsa-j88v-2chj-qfwx",
"ghsa-p77j-4mvh-x3m3",
"ghsa-pjcq-xvwq-hhpj",
"ghsa-wf45-q9ch-q8gh",
"ghsa-xmrv-pmrh-hhx2"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-UJ78067 (CVE-2025-22868)
Vulnerability from cleanstart – Published: 2026-09-10 02:56 – Updated: 2026-09-18 11:59 – Source websiteMultiple security vulnerabilities affect the stakater-reloader package. The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. See references for individual vulnerability details.
| URL | Type | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "stakater-reloader"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.4.8-r0"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"credits": [],
"database_specific": {},
"details": "Multiple security vulnerabilities affect the stakater-reloader package. The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. See references for individual vulnerability details.",
"id": "CLEANSTART-2026-UJ78067",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-09-10T02:56:12.067685Z",
"references": [
{
"type": "ADVISORY",
"url": "https://github.com/cleanstart-dev/cleanstart-security-advisories/tree/main/advisories/2026/CLEANSTART-2026-UJ78067.json"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-22868"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-47911"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-47912"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-58183"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-58185"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-58186"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-58187"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-58188"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-58189"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-58190"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-61723"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-61724"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-61725"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-61729"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-25679"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-27137"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-27138"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-27139"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-27142"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-33811"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-33814"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-33818"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39817"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39819"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39820"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39821"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39822"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39823"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39825"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39826"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39836"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42499"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42501"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42505"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-46600"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56852"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56853"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56858"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56859"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56860"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56862"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-259r-337f-4rfw"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-6v2p-p543-phr9"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22868"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47911"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47912"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58183"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58185"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58186"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58187"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58188"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58189"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58190"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61723"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61724"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61725"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61729"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25679"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27137"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27138"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27139"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27142"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33811"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33814"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33818"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39817"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39819"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39820"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39821"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39822"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39823"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39825"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39826"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39836"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42499"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42501"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42505"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46600"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56852"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56853"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56858"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56859"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56860"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56862"
}
],
"related": [],
"schema_version": "1.7.3",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"type": "CVSS_V3"
}
],
"summary": "ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label",
"upstream": [
"CVE-2025-22868",
"CVE-2025-47911",
"CVE-2025-47912",
"CVE-2025-58183",
"CVE-2025-58185",
"CVE-2025-58186",
"CVE-2025-58187",
"CVE-2025-58188",
"CVE-2025-58189",
"CVE-2025-58190",
"CVE-2025-61723",
"CVE-2025-61724",
"CVE-2025-61725",
"CVE-2025-61729",
"CVE-2026-25679",
"CVE-2026-27137",
"CVE-2026-27138",
"CVE-2026-27139",
"CVE-2026-27142",
"CVE-2026-33811",
"CVE-2026-33814",
"CVE-2026-33818",
"CVE-2026-39817",
"CVE-2026-39819",
"CVE-2026-39820",
"CVE-2026-39821",
"CVE-2026-39822",
"CVE-2026-39823",
"CVE-2026-39825",
"CVE-2026-39826",
"CVE-2026-39836",
"CVE-2026-42499",
"CVE-2026-42501",
"CVE-2026-42505",
"CVE-2026-46600",
"CVE-2026-56852",
"CVE-2026-56853",
"CVE-2026-56858",
"CVE-2026-56859",
"CVE-2026-56860",
"CVE-2026-56862",
"ghsa-259r-337f-4rfw",
"ghsa-6v2p-p543-phr9"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-UN51807 (CVE-2026-33818)
Vulnerability from cleanstart – Published: 2026-09-10 03:01 – Updated: 2026-09-18 11:59 – Source websiteMultiple security vulnerabilities affect the nats-streaming package. The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. See references for individual vulnerability details.
| URL | Type | |||||||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "nats-streaming"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.25.6-r6"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"credits": [],
"database_specific": {},
"details": "Multiple security vulnerabilities affect the nats-streaming package. The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. See references for individual vulnerability details.",
"id": "CLEANSTART-2026-UN51807",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-09-10T03:01:11.904847Z",
"references": [
{
"type": "ADVISORY",
"url": "https://github.com/cleanstart-dev/cleanstart-security-advisories/tree/main/advisories/2026/CLEANSTART-2026-UN51807.json"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-33818"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39821"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39822"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42504"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42505"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-46600"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56853"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56858"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-259r-337f-4rfw"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33818"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39821"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39822"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42504"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42505"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46600"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56853"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56858"
}
],
"related": [],
"schema_version": "1.7.3",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"type": "CVSS_V3"
}
],
"summary": "ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label",
"upstream": [
"CVE-2026-33818",
"CVE-2026-39821",
"CVE-2026-39822",
"CVE-2026-42504",
"CVE-2026-42505",
"CVE-2026-46600",
"CVE-2026-56853",
"CVE-2026-56858",
"ghsa-259r-337f-4rfw"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-UN57664 (CVE-2026-2303)
Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source websitePackage karma version 0.131-r1 fixes 6 vulnerabilities: CVE-2026-2303, CVE-2026-39824, ghsa-259r-337f-4rfw, ghsa-3fxj-6jh8-hvhx, ghsa-9g5q-2w5x-hmxf...
| URL | Type | |
|---|---|---|
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "karma"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.131-r1"
}
],
"type": "ECOSYSTEM"
}
],
"versions": [
"0.131-r1"
]
}
],
"credits": [],
"database_specific": {},
"details": "Package karma version 0.131-r1 fixes 6 vulnerabilities: CVE-2026-2303, CVE-2026-39824, ghsa-259r-337f-4rfw, ghsa-3fxj-6jh8-hvhx, ghsa-9g5q-2w5x-hmxf...",
"id": "CLEANSTART-2026-UN57664",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-09-01T11:17:16Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/prymitive/karma.git"
}
],
"related": [],
"schema_version": "1.7.3",
"summary": "Security fixes in karma 0.131-r1",
"upstream": [
"CVE-2026-2303",
"CVE-2026-39824",
"ghsa-259r-337f-4rfw",
"ghsa-3fxj-6jh8-hvhx",
"ghsa-9g5q-2w5x-hmxf",
"ghsa-rjr7-jggh-pgcp"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-UW32521 (GHSA-259R-337F-4RFW)
Vulnerability from cleanstart – Published: 2026-09-18 09:53 – Updated: 2026-07-31 04:15 – Source websiteghsa-259r-337f-4rfw affects multiple packages. This issue is resolved in later releases. See references for individual vulnerability details.
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "amazon-cloudwatch-agent"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.300070.0-r1"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "amazon-cloudwatch-agent"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.300071.0-r1"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "argo-cd"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "3.1.16-r4"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "argo-cd"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "3.2.12-r3"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "argo-cd"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "3.3.12-r4"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "argo-cd"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "3.3.14-r2"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "argo-cd"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "3.4.5-r2"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "argo-cd"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "3.4.6-r0"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "argo-cd"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "3.4.7-r2"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "argo-cd-fips"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "3.4.7-r1"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "argo-workflows"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "3.7.17-r2"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "cadvisor"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.55.1-r4"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "cadvisor"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.56.2-r2"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "cadvisor"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.57.0-r4"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "cadvisor"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.60.5-r0"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "calico"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "3.30.7-r6"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "cert-manager"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.17.4-r5"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "cert-manager"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.18.6-r4"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "cortex"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.18.1-r4"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "cortex"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.19.1-r2"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "cortex"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.20.1-r3"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "cosign"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "3.1.2-r1"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "crossplane"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "2.3.4-r2"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "dex"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "2.42.1-r2"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "dynatrace-operator"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.8.1-r6"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "dynatrace-operator"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.9.0-r4"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "elastic-beats"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "9.1.10-r5"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "elastic-beats"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "9.2.8-r7"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "elastic-beats"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "9.3.7-r1"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "elastic-beats"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "9.3.9-r0"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "elastic-beats"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "9.4.2-r3"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "flux-notification-controller-fips"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.9.2-r0"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "fulcio-fips"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.6.6-r3"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "gitea"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.26.4-r1"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "gitea"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.27.0-r2"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "gitea"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.27.2-r1"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "grafana"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "12.3.10-r1"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "grafana"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "12.3.8-r2"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "grafana"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "12.4.5-r2"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "grafana"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "12.4.6-r0"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "grafana"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "12.4.7-r1"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "grafana"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "12.4.9-r1"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "grafana"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "13.0.5-r1"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "grafana"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "13.0.7-r1"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "haproxy-ingress"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.14.12-r2"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "helm-operator"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.39.2-r1"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "helm-operator"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.40.0-r1"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "istio"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.29.6-r2"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "karma"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.128-r1"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "karma"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.129-r1"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "karma"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.130-r1"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "karma"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.131-r1"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "knative-net-istio"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.21.4-r2"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "knative-serving"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.20.3-r0"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "kube-metrics-adapter"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.2.9-r1"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "kubernetes-dns-node-cache"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.23.1-r1"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "kubernetes-dns-node-cache"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.24.1-r2"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "kubernetes-dns-node-cache"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.25.0-r9"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "kubernetes-dns-node-cache"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.26.8-r6"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "kubernetes-event-exporter"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.5-r3"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "kyverno"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.16.4-r3"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "kyverno"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.17.2-r2"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "kyverno"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.18.1-r3"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "local-path-provisioner-fips"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.0.36-r1"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "logstash-exporter"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.7.1-r1"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "logstash-exporter"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.8.4-r1"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "loki"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "3.6.12-r2"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "minio-operator"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "6.0.4-r6"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "minio-operator"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "7.0.1-r7"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "mongodb"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "8.1.3-r3"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "mongodb"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "8.3.7-r0"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "nats-streaming"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.22.1-r1"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "nats-streaming"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.23.2-r1"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "nats-streaming"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.24.6-r4"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "nats-streaming"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.25.6-r5"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "newrelic-infrastructure-agent"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.76.2-r1"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "newrelic-infrastructure-agent"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.78.1-r1"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "newrelic-infrastructure-agent"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.79.0-r1"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "ollama"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.31.2-r1"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "ollama"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.32.0-r1"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "ollama"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.32.11-r3"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "ollama"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.32.4-r1"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "ollama"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.32.7-r1"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "ollama"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.32.9-r1"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "ollama-fips"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.30.11-r2"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "ollama-fips"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.32.1-r1"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "ollama-fips"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.32.11-r2"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "ollama-fips"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.32.14-r2"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "ollama-fips"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.32.4-r1"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "ollama-fips"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.32.7-r1"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "ollama-fips"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.32.8-r1"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "ollama-fips"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.32.9-r2"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "opentelemetry-collector-contrib"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.153.0-r3"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "opentelemetry-collector-contrib"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.155.0-r1"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "percona-server-mongodb-operator"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.23.0-r0"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "policy-controller-fips"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.15.1-r1"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "prometheus"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "3.10.0-r7"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "prometheus"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "3.11.3-r5"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "prometheus"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "3.13.1-r2"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "prometheus"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "3.5.3-r6"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "prometheus"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "3.9.1-r9"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "prometheus-alertmanager"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.33.0-r2"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "prometheus-fips"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "3.10.0-r1"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "prometheus-fips"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "3.11.3-r1"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "prometheus-fips"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "3.12.0-r1"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "prometheus-mysqld-exporter"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.16.0-r4"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "prometheus-mysqld-exporter"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.17.2-r4"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "prometheus-pushgateway"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.10.0-r3"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "prometheus-redis-exporter"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.85.0-r1"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "prometheus-redis-exporter"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.86.0-r1"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "prometheus-redis-exporter"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.88.0-r2"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "prometheus-redis-exporter-fips"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.87.0-r1"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "prometheus-statsd-exporter"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.27.2-r1"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "prometheus-statsd-exporter"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.28.0-r3"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "pulumi"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "3.248.0-r0"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "rabbitmq-messaging-topology-operator"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.16.0-r2"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "rancher-agent"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "2.11.15-r1"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "rancher-agent"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "2.12.11-r1"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "rancher-agent"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "2.13.7-r3"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "rancher-agent"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "2.14.3-r0"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "rancher-fleet-agent"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.12.17-r1"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "rancher-fleet-agent"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.14.10-r1"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "rancher-fleet-agent"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.14.8-r1"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "rancher-fleet-agent"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.15.4-r1"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "rancher-fleet-agent"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.15.6-r0"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "rancher-fleet-agent"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.16.1-r1"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "rclone"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.71.2-r3"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "rclone"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.72.1-r11"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "rclone"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.73.5-r5"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "rclone"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.74.3-r2"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "spire-server"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.14.7-r0"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "stakater-reloader"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.1.0-r3"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "stakater-reloader"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.2.1-r2"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "stakater-reloader"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.3.0-r2"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "step"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.27.5-r3"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "step"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.28.7-r4"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "step"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.29.0-r3"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "step-ca"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.27.5-r0"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "step-cli"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.27.5-r1"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "step-cli"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.30.6-r0"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "step-issuer"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.11.0-r4"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "step-issuer"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.9.11-r2"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "tekton-chains"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.25.2-r1"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "tekton-chains-fips"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.24.0-r1"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "tekton-chains-fips"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.25.2-r1"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "tekton-chains-fips"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.26.5-r1"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "tempo"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "2.10.7-r2"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "tempo"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "2.10.8-r1"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "tempo"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "2.9.5-r2"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "temporal-server"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.28.4-r2"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "temporal-server"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.29.7-r2"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "temporal-server"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.30.5-r1"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "temporal-server"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.30.6-r3"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "terraform"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.15.7-r0"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "tigera-operator"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.39.3-r1"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "tigera-operator"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.40.13-r1"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "tigera-operator"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.42.1-r2"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "tigera-operator"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.42.3-r2"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "tkn"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.42.2-r1"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "tkn"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.43.2-r1"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "tkn"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.44.2-r1"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "tkn"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.45.0-r1"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "vault"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.19.5-r1"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "vault"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.20.4-r8"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "vault"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.21.4-r9"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "vault"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "2.0.3-r1"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "vault-k8s"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.5.0-r2"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "vault-k8s"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.6.2-r1"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "velero"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.15.2-r6"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "velero"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.17.2-r7"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "velero"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.18.2-r6"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "victoriametrics-operator"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.71.0-r2"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "victoriametrics-operator-fips"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.69.0-r0"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "victoriametrics-operator-fips"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.70.1-r0"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "victoriametrics-operator-fips"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.71.0-r0"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "victoriametrics-operator-fips"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.72.0-r1"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "wave"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.10.0-r4"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "weaviate-fips"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.37.14-r0"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "CleanStart",
"name": "weaviate-fips"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.38.6-r1"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"credits": [],
"database_specific": {},
"details": "ghsa-259r-337f-4rfw affects multiple packages. This issue is resolved in later releases. See references for individual vulnerability details.",
"id": "CLEANSTART-2026-UW32521",
"modified": "2026-07-31T04:15:06Z",
"published": "2026-09-18T09:53:24.548311Z",
"references": [
{
"type": "ADVISORY",
"url": "https://github.com/cleanstart-dev/cleanstart-security-advisories/tree/main/advisories/2026/CLEANSTART-2026-UW32521.json"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-259r-337f-4rfw"
}
],
"related": [],
"schema_version": "1.7.3",
"summary": "Security fix for ghsa-259r-337f-4rfw applied in: amazon-cloudwatch-agent 1.300070.0-r1, amazon-cloudwatch-agent 1.300071.0-r1, argo-cd 3.1.16-r4, argo-cd 3.2.12-r3, argo-cd 3.3.12-r4, argo-cd 3.3.14-r2, argo-cd 3.4.5-r2, argo-cd 3.4.6-r0, argo-cd 3.4.7-r2, argo-cd-fips 3.4.7-r1, argo-workflows 3.7.17-r2, cadvisor 0.55.1-r4, cadvisor 0.56.2-r2, cadvisor 0.57.0-r4, cadvisor 0.60.5-r0, calico 3.30.7-r6, cert-manager 1.17.4-r5, cert-manager 1.18.6-r4, cortex 1.18.1-r4, cortex 1.19.1-r2, cortex 1.20.1-r3, cosign 3.1.2-r1, crossplane 2.3.4-r2, dex 2.42.1-r2, dynatrace-operator 1.8.1-r6, dynatrace-operator 1.9.0-r4, elastic-beats 9.1.10-r5, elastic-beats 9.2.8-r7, elastic-beats 9.3.7-r1, elastic-beats 9.3.9-r0, elastic-beats 9.4.2-r3, flux-notification-controller-fips 1.9.2-r0, fulcio-fips 1.6.6-r3, gitea 1.26.4-r1, gitea 1.27.0-r2, gitea 1.27.2-r1, grafana 12.3.10-r1, grafana 12.3.8-r2, grafana 12.4.5-r2, grafana 12.4.6-r0, grafana 12.4.7-r1, grafana 12.4.9-r1, grafana 13.0.5-r1, grafana 13.0.7-r1, haproxy-ingress 0.14.12-r2, helm-operator 1.39.2-r1, helm-operator 1.40.0-r1, istio 1.29.6-r2, karma 0.128-r1, karma 0.129-r1, karma 0.130-r1, karma 0.131-r1, knative-net-istio 1.21.4-r2, knative-serving 1.20.3-r0, kube-metrics-adapter 0.2.9-r1, kubernetes-dns-node-cache 1.23.1-r1, kubernetes-dns-node-cache 1.24.1-r2, kubernetes-dns-node-cache 1.25.0-r9, kubernetes-dns-node-cache 1.26.8-r6, kubernetes-event-exporter 1.5-r3, kyverno 1.16.4-r3, kyverno 1.17.2-r2, kyverno 1.18.1-r3, local-path-provisioner-fips 0.0.36-r1, logstash-exporter 1.7.1-r1, logstash-exporter 1.8.4-r1, loki 3.6.12-r2, minio-operator 6.0.4-r6, minio-operator 7.0.1-r7, mongodb 8.1.3-r3, mongodb 8.3.7-r0, nats-streaming 0.22.1-r1, nats-streaming 0.23.2-r1, nats-streaming 0.24.6-r4, nats-streaming 0.25.6-r5, newrelic-infrastructure-agent 1.76.2-r1, newrelic-infrastructure-agent 1.78.1-r1, newrelic-infrastructure-agent 1.79.0-r1, ollama 0.31.2-r1, ollama 0.32.0-r1, ollama 0.32.11-r3, ollama 0.32.4-r1, ollama 0.32.7-r1, ollama 0.32.9-r1, ollama-fips 0.30.11-r2, ollama-fips 0.32.1-r1, ollama-fips 0.32.11-r2, ollama-fips 0.32.14-r2, ollama-fips 0.32.4-r1, ollama-fips 0.32.7-r1, ollama-fips 0.32.8-r1, ollama-fips 0.32.9-r2, opentelemetry-collector-contrib 0.153.0-r3, opentelemetry-collector-contrib 0.155.0-r1, percona-server-mongodb-operator 1.23.0-r0, policy-controller-fips 0.15.1-r1, prometheus 3.10.0-r7, prometheus 3.11.3-r5, prometheus 3.13.1-r2, prometheus 3.5.3-r6, prometheus 3.9.1-r9, prometheus-alertmanager 0.33.0-r2, prometheus-fips 3.10.0-r1, prometheus-fips 3.11.3-r1, prometheus-fips 3.12.0-r1, prometheus-mysqld-exporter 0.16.0-r4, prometheus-mysqld-exporter 0.17.2-r4, prometheus-pushgateway 1.10.0-r3, prometheus-redis-exporter 1.85.0-r1, prometheus-redis-exporter 1.86.0-r1, prometheus-redis-exporter 1.88.0-r2, prometheus-redis-exporter-fips 1.87.0-r1, prometheus-statsd-exporter 0.27.2-r1, prometheus-statsd-exporter 0.28.0-r3, pulumi 3.248.0-r0, rabbitmq-messaging-topology-operator 1.16.0-r2, rancher-agent 2.11.15-r1, rancher-agent 2.12.11-r1, rancher-agent 2.13.7-r3, rancher-agent 2.14.3-r0, rancher-fleet-agent 0.12.17-r1, rancher-fleet-agent 0.14.10-r1, rancher-fleet-agent 0.14.8-r1, rancher-fleet-agent 0.15.4-r1, rancher-fleet-agent 0.15.6-r0, rancher-fleet-agent 0.16.1-r1, rclone 1.71.2-r3, rclone 1.72.1-r11, rclone 1.73.5-r5, rclone 1.74.3-r2, spire-server 1.14.7-r0, stakater-reloader 1.1.0-r3, stakater-reloader 1.2.1-r2, stakater-reloader 1.3.0-r2, step 0.27.5-r3, step 0.28.7-r4, step 0.29.0-r3, step-ca 0.27.5-r0, step-cli 0.27.5-r1, step-cli 0.30.6-r0, step-issuer 0.11.0-r4, step-issuer 0.9.11-r2, tekton-chains 0.25.2-r1, tekton-chains-fips 0.24.0-r1, tekton-chains-fips 0.25.2-r1, tekton-chains-fips 0.26.5-r1, tempo 2.10.7-r2, tempo 2.10.8-r1, tempo 2.9.5-r2, temporal-server 1.28.4-r2, temporal-server 1.29.7-r2, temporal-server 1.30.5-r1, temporal-server 1.30.6-r3, terraform 1.15.7-r0, tigera-operator 1.39.3-r1, tigera-operator 1.40.13-r1, tigera-operator 1.42.1-r2, tigera-operator 1.42.3-r2, tkn 0.42.2-r1, tkn 0.43.2-r1, tkn 0.44.2-r1, tkn 0.45.0-r1, vault 1.19.5-r1, vault 1.20.4-r8, vault 1.21.4-r9, vault 2.0.3-r1, vault-k8s 1.5.0-r2, vault-k8s 1.6.2-r1, velero 1.15.2-r6, velero 1.17.2-r7, velero 1.18.2-r6, victoriametrics-operator 0.71.0-r2, victoriametrics-operator-fips 0.69.0-r0, victoriametrics-operator-fips 0.70.1-r0, victoriametrics-operator-fips 0.71.0-r0, victoriametrics-operator-fips 0.72.0-r1, wave 0.10.0-r4, weaviate-fips 1.37.14-r0, weaviate-fips 1.38.6-r1",
"upstream": [
"ghsa-259r-337f-4rfw"
]
}
CLEANSTART-2026-UW93671 (GHSA-259R-337F-4RFW)
Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source websitePackage prometheus-redis-exporter version 1.88.0-r2 fixes 1 vulnerabilities: ghsa-259r-337f-4rfw
| URL | Type | |
|---|---|---|
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "prometheus-redis-exporter"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.88.0-r2"
}
],
"type": "ECOSYSTEM"
}
],
"versions": [
"1.88.0-r2"
]
}
],
"credits": [],
"database_specific": {},
"details": "Package prometheus-redis-exporter version 1.88.0-r2 fixes 1 vulnerabilities: ghsa-259r-337f-4rfw",
"id": "CLEANSTART-2026-UW93671",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-09-01T11:17:16Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/oliver006/redis_exporter"
}
],
"related": [],
"schema_version": "1.7.3",
"summary": "Security fixes in prometheus-redis-exporter 1.88.0-r2",
"upstream": [
"ghsa-259r-337f-4rfw"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-UZ65030 (CVE-2026-33818)
Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source websitePackage tkn version 0.44.2-r1 fixes 27 vulnerabilities: CVE-2026-33818, CVE-2026-56853, CVE-2026-56858, CVE-2026-56859, CVE-2026-56860...
| URL | Type | |
|---|---|---|
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "tkn"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.44.2-r1"
}
],
"type": "ECOSYSTEM"
}
],
"versions": [
"0.44.2-r1"
]
}
],
"credits": [],
"database_specific": {},
"details": "Package tkn version 0.44.2-r1 fixes 27 vulnerabilities: CVE-2026-33818, CVE-2026-56853, CVE-2026-56858, CVE-2026-56859, CVE-2026-56860...",
"id": "CLEANSTART-2026-UZ65030",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-09-01T11:17:16Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/tektoncd/cli"
}
],
"related": [],
"schema_version": "1.7.3",
"summary": "Security fixes in tkn 0.44.2-r1",
"upstream": [
"CVE-2026-33818",
"CVE-2026-56853",
"CVE-2026-56858",
"CVE-2026-56859",
"CVE-2026-56860",
"CVE-2026-56862",
"CVE-2026-39821",
"CVE-2026-34040",
"CVE-2026-33997",
"ghsa-gcjh-h69q-9w9g",
"ghsa-pmwq-pjrm-6p5r",
"CVE-2026-49478",
"CVE-2026-48702",
"CVE-2026-49834",
"CVE-2026-54787",
"CVE-2026-39984",
"CVE-2026-49835",
"CVE-2026-2303",
"CVE-2026-46600",
"CVE-2026-56852",
"ghsa-hrxh-6v49-42gf",
"CVE-2026-56864",
"CVE-2026-56865",
"ghsa-259r-337f-4rfw",
"ghsa-3fxj-6jh8-hvhx",
"ghsa-9g5q-2w5x-hmxf",
"ghsa-rjr7-jggh-pgcp"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-VB09315 (CVE-2026-33186)
Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source websitePackage rancher-fleet-agent version 0.12.17-r1 fixes 40 vulnerabilities: CVE-2026-33186, ghsa-hrxh-6v49-42gf, CVE-2026-46680, CVE-2026-53488, CVE-2026-47262...
| URL | Type | |
|---|---|---|
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "rancher-fleet-agent"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.12.17-r1"
}
],
"type": "ECOSYSTEM"
}
],
"versions": [
"0.12.17-r1"
]
}
],
"credits": [],
"database_specific": {},
"details": "Package rancher-fleet-agent version 0.12.17-r1 fixes 40 vulnerabilities: CVE-2026-33186, ghsa-hrxh-6v49-42gf, CVE-2026-46680, CVE-2026-53488, CVE-2026-47262...",
"id": "CLEANSTART-2026-VB09315",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-09-01T11:17:16Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/rancher/fleet"
}
],
"related": [],
"schema_version": "1.7.3",
"summary": "Security fixes in rancher-fleet-agent 0.12.17-r1",
"upstream": [
"CVE-2026-33186",
"ghsa-hrxh-6v49-42gf",
"CVE-2026-46680",
"CVE-2026-53488",
"CVE-2026-47262",
"CVE-2026-50195",
"CVE-2026-53492",
"CVE-2026-53489",
"CVE-2026-39835",
"CVE-2026-39828",
"CVE-2026-39829",
"CVE-2026-46597",
"CVE-2026-39830",
"CVE-2026-39831",
"CVE-2026-39832",
"CVE-2026-39833",
"CVE-2026-39834",
"CVE-2026-42508",
"CVE-2026-46595",
"CVE-2026-46598",
"CVE-2026-39827",
"CVE-2026-25681",
"CVE-2026-27136",
"CVE-2026-39821",
"CVE-2026-42502",
"CVE-2026-42506",
"CVE-2026-25680",
"CVE-2026-33814",
"CVE-2026-46600",
"CVE-2026-29181",
"CVE-2026-35469",
"CVE-2026-56852",
"CVE-2026-50163",
"CVE-2026-50151",
"CVE-2026-50162",
"ghsa-vh4v-2xq2-g5cg",
"CVE-2026-48978",
"CVE-2026-35206",
"ghsa-259r-337f-4rfw",
"CVE-2026-39824"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-VD81951 (CVE-2026-41178)
Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source websitePackage fulcio-fips version 1.6.6-r3 fixes 7 vulnerabilities: CVE-2026-41178, ghsa-hrxh-6v49-42gf, ghsa-259r-337f-4rfw, CVE-2026-24137, CVE-2026-39821...
| URL | Type | |
|---|---|---|
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "fulcio-fips"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.6.6-r3"
}
],
"type": "ECOSYSTEM"
}
],
"versions": [
"1.6.6-r3"
]
}
],
"credits": [],
"database_specific": {},
"details": "Package fulcio-fips version 1.6.6-r3 fixes 7 vulnerabilities: CVE-2026-41178, ghsa-hrxh-6v49-42gf, ghsa-259r-337f-4rfw, CVE-2026-24137, CVE-2026-39821...",
"id": "CLEANSTART-2026-VD81951",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-09-01T11:17:16Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/sigstore/fulcio"
}
],
"related": [],
"schema_version": "1.7.3",
"summary": "Security fixes in fulcio-fips 1.6.6-r3",
"upstream": [
"CVE-2026-41178",
"ghsa-hrxh-6v49-42gf",
"ghsa-259r-337f-4rfw",
"CVE-2026-24137",
"CVE-2026-39821",
"CVE-2026-46600",
"CVE-2026-33186"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-VI74714 (GHSA-R277-6W6Q-XMQW)
Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source websitePackage grafana version 13.0.5-r1 fixes 8 vulnerabilities: ghsa-r277-6w6q-xmqw, ghsa-jpcw-4wr7-c3vq, CVE-2026-21728, CVE-2026-28377, CVE-2026-42151...
| URL | Type | |
|---|---|---|
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "grafana"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "13.0.5-r1"
}
],
"type": "ECOSYSTEM"
}
],
"versions": [
"13.0.5-r1"
]
}
],
"credits": [],
"database_specific": {},
"details": "Package grafana version 13.0.5-r1 fixes 8 vulnerabilities: ghsa-r277-6w6q-xmqw, ghsa-jpcw-4wr7-c3vq, CVE-2026-21728, CVE-2026-28377, CVE-2026-42151...",
"id": "CLEANSTART-2026-VI74714",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-09-01T11:17:16Z",
"references": [
{
"type": "WEB",
"url": "https://grafana.com"
}
],
"related": [],
"schema_version": "1.7.3",
"summary": "Security fixes in grafana 13.0.5-r1",
"upstream": [
"ghsa-r277-6w6q-xmqw",
"ghsa-jpcw-4wr7-c3vq",
"CVE-2026-21728",
"CVE-2026-28377",
"CVE-2026-42151",
"CVE-2026-40179",
"CVE-2026-44903",
"ghsa-259r-337f-4rfw"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-VK86621 (CVE-2026-39821)
Vulnerability from cleanstart – Published: 2026-09-18 01:13 – Updated: 2026-09-18 11:59 – Source websiteMultiple security vulnerabilities affect the dynatrace-operator package. The source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for CVE-2026-46595. See references for individual vulnerability details.
| URL | Type | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "dynatrace-operator"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.9.0-r6"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"credits": [],
"database_specific": {},
"details": "Multiple security vulnerabilities affect the dynatrace-operator package. The source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for CVE-2026-46595. See references for individual vulnerability details.",
"id": "CLEANSTART-2026-VK86621",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-09-18T01:13:28.670790Z",
"references": [
{
"type": "ADVISORY",
"url": "https://github.com/cleanstart-dev/cleanstart-security-advisories/tree/main/advisories/2026/CLEANSTART-2026-VK86621.json"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39821"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-41178"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-46600"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56854"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56855"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56859"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56860"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56864"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-78662"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-84303"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-84304"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-84445"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-259r-337f-4rfw"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39821"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41178"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46600"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56854"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56855"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56859"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56860"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56864"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78662"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84303"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84304"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84445"
}
],
"related": [],
"schema_version": "1.7.3",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"type": "CVSS_V3"
}
],
"summary": "source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for CVE-2...",
"upstream": [
"CVE-2026-39821",
"CVE-2026-41178",
"CVE-2026-46600",
"CVE-2026-56854",
"CVE-2026-56855",
"CVE-2026-56859",
"CVE-2026-56860",
"CVE-2026-56864",
"CVE-2026-78662",
"CVE-2026-84303",
"CVE-2026-84304",
"CVE-2026-84445",
"ghsa-259r-337f-4rfw"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-VO98287 (CVE-2025-63811)
Vulnerability from cleanstart – Published: 2026-09-10 02:48 – Updated: 2026-09-18 11:59 – Source websiteMultiple security vulnerabilities affect the vault package. Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. See references for individual vulnerability details.
| URL | Type | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "vault"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.21.4-r0"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"credits": [],
"database_specific": {},
"details": "Multiple security vulnerabilities affect the vault package. Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. See references for individual vulnerability details.",
"id": "CLEANSTART-2026-VO98287",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-09-10T02:48:15.538252Z",
"references": [
{
"type": "ADVISORY",
"url": "https://github.com/cleanstart-dev/cleanstart-security-advisories/tree/main/advisories/2026/CLEANSTART-2026-VO98287.json"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-63811"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-1229"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-2303"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-24051"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-25680"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-25681"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-26958"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-27136"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-27145"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-32280"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-32281"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-32282"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-32283"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-32288"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-32289"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-32952"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-33186"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-33810"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-33811"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-33814"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-33816"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-33818"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-34986"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39817"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39819"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39820"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39821"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39822"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39823"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39824"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39825"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39826"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39827"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39828"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39829"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39830"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39831"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39832"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39833"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39834"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39835"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39836"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39883"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-41178"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-41602"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-41889"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42499"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42501"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42502"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42504"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42505"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42506"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42507"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42508"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-44503"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-46595"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-46597"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-46598"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-46600"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56852"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56853"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56854"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56855"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56858"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56859"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56860"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56862"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-73500"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-78662"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-84304"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-259r-337f-4rfw"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-78h2-9frx-2jm8"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-7j59-v9qr-6fq9"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-cp6g-7hqx-qxhp"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-j88v-2chj-qfwx"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-p77j-4mvh-x3m3"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-pjcq-xvwq-hhpj"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-w67g-5rqw-f597"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-wf45-q9ch-q8gh"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-xmrv-pmrh-hhx2"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-63811"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-1229"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-2303"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-24051"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25680"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25681"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-26958"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27136"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27145"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32280"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32281"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32282"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32283"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32288"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32289"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32952"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33186"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33810"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33811"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33814"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33816"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33818"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-34986"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39817"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39819"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39820"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39821"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39822"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39823"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39824"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39825"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39826"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39827"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39828"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39829"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39830"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39831"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39832"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39833"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39834"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39835"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39836"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39883"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41178"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41602"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41889"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42499"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42501"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42502"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42504"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42505"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42506"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42507"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42508"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-44503"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46595"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46597"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46598"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46600"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56852"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56853"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56854"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56855"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56858"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56859"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56860"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56862"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-73500"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78662"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84304"
}
],
"related": [],
"schema_version": "1.7.3",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"type": "CVSS_V3"
}
],
"summary": "Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection",
"upstream": [
"CVE-2025-63811",
"CVE-2026-1229",
"CVE-2026-2303",
"CVE-2026-24051",
"CVE-2026-25680",
"CVE-2026-25681",
"CVE-2026-26958",
"CVE-2026-27136",
"CVE-2026-27145",
"CVE-2026-32280",
"CVE-2026-32281",
"CVE-2026-32282",
"CVE-2026-32283",
"CVE-2026-32288",
"CVE-2026-32289",
"CVE-2026-32952",
"CVE-2026-33186",
"CVE-2026-33810",
"CVE-2026-33811",
"CVE-2026-33814",
"CVE-2026-33816",
"CVE-2026-33818",
"CVE-2026-34986",
"CVE-2026-39817",
"CVE-2026-39819",
"CVE-2026-39820",
"CVE-2026-39821",
"CVE-2026-39822",
"CVE-2026-39823",
"CVE-2026-39824",
"CVE-2026-39825",
"CVE-2026-39826",
"CVE-2026-39827",
"CVE-2026-39828",
"CVE-2026-39829",
"CVE-2026-39830",
"CVE-2026-39831",
"CVE-2026-39832",
"CVE-2026-39833",
"CVE-2026-39834",
"CVE-2026-39835",
"CVE-2026-39836",
"CVE-2026-39883",
"CVE-2026-41178",
"CVE-2026-41602",
"CVE-2026-41889",
"CVE-2026-42499",
"CVE-2026-42501",
"CVE-2026-42502",
"CVE-2026-42504",
"CVE-2026-42505",
"CVE-2026-42506",
"CVE-2026-42507",
"CVE-2026-42508",
"CVE-2026-44503",
"CVE-2026-46595",
"CVE-2026-46597",
"CVE-2026-46598",
"CVE-2026-46600",
"CVE-2026-56852",
"CVE-2026-56853",
"CVE-2026-56854",
"CVE-2026-56855",
"CVE-2026-56858",
"CVE-2026-56859",
"CVE-2026-56860",
"CVE-2026-56862",
"CVE-2026-73500",
"CVE-2026-78662",
"CVE-2026-84304",
"ghsa-259r-337f-4rfw",
"ghsa-78h2-9frx-2jm8",
"ghsa-7j59-v9qr-6fq9",
"ghsa-cp6g-7hqx-qxhp",
"ghsa-j88v-2chj-qfwx",
"ghsa-p77j-4mvh-x3m3",
"ghsa-pjcq-xvwq-hhpj",
"ghsa-w67g-5rqw-f597",
"ghsa-wf45-q9ch-q8gh",
"ghsa-xmrv-pmrh-hhx2"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-VU77552 (GHSA-R277-6W6Q-XMQW)
Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source websitePackage grafana version 13.0.7-r1 fixes 8 vulnerabilities: ghsa-r277-6w6q-xmqw, CVE-2026-73502, CVE-2026-42151, CVE-2026-44903, CVE-2026-40179...
| URL | Type | |
|---|---|---|
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "grafana"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "13.0.7-r1"
}
],
"type": "ECOSYSTEM"
}
],
"versions": [
"13.0.7-r1"
]
}
],
"credits": [],
"database_specific": {},
"details": "Package grafana version 13.0.7-r1 fixes 8 vulnerabilities: ghsa-r277-6w6q-xmqw, CVE-2026-73502, CVE-2026-42151, CVE-2026-44903, CVE-2026-40179...",
"id": "CLEANSTART-2026-VU77552",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-09-01T11:17:16Z",
"references": [
{
"type": "WEB",
"url": "https://grafana.com"
}
],
"related": [],
"schema_version": "1.7.3",
"summary": "Security fixes in grafana 13.0.7-r1",
"upstream": [
"ghsa-r277-6w6q-xmqw",
"CVE-2026-73502",
"CVE-2026-42151",
"CVE-2026-44903",
"CVE-2026-40179",
"CVE-2026-21728",
"CVE-2026-28377",
"ghsa-259r-337f-4rfw"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-VW52056 (GHSA-259R-337F-4RFW)
Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source websitePackage ollama version 0.32.7-r1 fixes 1 vulnerabilities: ghsa-259r-337f-4rfw
| URL | Type | |
|---|---|---|
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "ollama"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.32.7-r1"
}
],
"type": "ECOSYSTEM"
}
],
"versions": [
"0.32.7-r1"
]
}
],
"credits": [],
"database_specific": {},
"details": "Package ollama version 0.32.7-r1 fixes 1 vulnerabilities: ghsa-259r-337f-4rfw",
"id": "CLEANSTART-2026-VW52056",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-09-01T11:17:16Z",
"references": [
{
"type": "WEB",
"url": "https://ollama.com"
}
],
"related": [],
"schema_version": "1.7.3",
"summary": "Security fixes in ollama 0.32.7-r1",
"upstream": [
"ghsa-259r-337f-4rfw"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-VZ50651 (CVE-2026-2303)
Vulnerability from cleanstart – Published: 2026-08-13 12:10 – Updated: 2026-09-18 11:59 – Source websitePackage mongodb version 8.3.7-r0 fixes 2 vulnerabilities: CVE-2026-2303, ghsa-259r-337f-4rfw
| URL | Type | |
|---|---|---|
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "mongodb"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "8.3.7-r0"
}
],
"type": "ECOSYSTEM"
}
],
"versions": [
"8.3.7-r0"
]
}
],
"credits": [],
"database_specific": {},
"details": "Package mongodb version 8.3.7-r0 fixes 2 vulnerabilities: CVE-2026-2303, ghsa-259r-337f-4rfw",
"id": "CLEANSTART-2026-VZ50651",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-08-13T12:10:09Z",
"references": [
{
"type": "WEB",
"url": "https://www.mongodb.org"
}
],
"related": [],
"schema_version": "1.7.3",
"summary": "Security fixes in mongodb 8.3.7-r0",
"upstream": [
"CVE-2026-2303",
"ghsa-259r-337f-4rfw"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-WM20973 (CVE-2026-39828)
Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source websitePackage ollama-fips version 0.32.11-r2 fixes 33 vulnerabilities: CVE-2026-39828, CVE-2026-39829, CVE-2026-39830, CVE-2026-39831, CVE-2026-39832...
| URL | Type | |
|---|---|---|
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "ollama-fips"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.32.11-r2"
}
],
"type": "ECOSYSTEM"
}
],
"versions": [
"0.32.11-r2"
]
}
],
"credits": [],
"database_specific": {},
"details": "Package ollama-fips version 0.32.11-r2 fixes 33 vulnerabilities: CVE-2026-39828, CVE-2026-39829, CVE-2026-39830, CVE-2026-39831, CVE-2026-39832...",
"id": "CLEANSTART-2026-WM20973",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-09-01T11:17:16Z",
"references": [
{
"type": "WEB",
"url": "https://ollama.com"
}
],
"related": [],
"schema_version": "1.7.3",
"summary": "Security fixes in ollama-fips 0.32.11-r2",
"upstream": [
"CVE-2026-39828",
"CVE-2026-39829",
"CVE-2026-39830",
"CVE-2026-39831",
"CVE-2026-39832",
"CVE-2026-39835",
"CVE-2026-42508",
"CVE-2026-46595",
"CVE-2026-46597",
"CVE-2026-39827",
"CVE-2026-39833",
"CVE-2026-39834",
"CVE-2026-46598",
"CVE-2026-46602",
"CVE-2026-33809",
"CVE-2026-33812",
"CVE-2026-33813",
"CVE-2026-46599",
"CVE-2026-46601",
"CVE-2026-46604",
"CVE-2026-42500",
"CVE-2026-25681",
"CVE-2026-27136",
"CVE-2026-33814",
"CVE-2026-39821",
"CVE-2026-46600",
"CVE-2026-25680",
"CVE-2026-42502",
"CVE-2026-42506",
"CVE-2026-56852",
"CVE-2026-56864",
"CVE-2026-56865",
"ghsa-259r-337f-4rfw"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-WM58118 (GHSA-259R-337F-4RFW)
Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source websitePackage rancher-agent version 2.13.7-r3 fixes 1 vulnerabilities: ghsa-259r-337f-4rfw
| URL | Type | |
|---|---|---|
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "rancher-agent"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "2.13.7-r3"
}
],
"type": "ECOSYSTEM"
}
],
"versions": [
"2.13.7-r3"
]
}
],
"credits": [],
"database_specific": {},
"details": "Package rancher-agent version 2.13.7-r3 fixes 1 vulnerabilities: ghsa-259r-337f-4rfw",
"id": "CLEANSTART-2026-WM58118",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-09-01T11:17:16Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/rancher/rancher"
}
],
"related": [],
"schema_version": "1.7.3",
"summary": "Security fixes in rancher-agent 2.13.7-r3",
"upstream": [
"ghsa-259r-337f-4rfw"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-WM90638 (GHSA-259R-337F-4RFW)
Vulnerability from cleanstart – Published: 2026-09-29 00:35 – Updated: 2026-09-28 06:30 – Source websiteSecurity vulnerability affects the grafana-alloy package. This issue is resolved in later releases. See references for vulnerability details.
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "grafana-alloy"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.16.3-r0"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"credits": [],
"database_specific": {},
"details": "Security vulnerability affects the grafana-alloy package. This issue is resolved in later releases. See references for vulnerability details.",
"id": "CLEANSTART-2026-WM90638",
"modified": "2026-09-28T06:30:11Z",
"published": "2026-09-29T00:35:03.276396Z",
"references": [
{
"type": "ADVISORY",
"url": "https://github.com/cleanstart-dev/cleanstart-security-advisories/tree/main/advisories/2026/CLEANSTART-2026-WM90638.json"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-259r-337f-4rfw"
}
],
"related": [],
"schema_version": "1.7.3",
"summary": "Security fix for ghsa-259r-337f-4rfw applied in: grafana-alloy 1.16.3-r0",
"upstream": [
"ghsa-259r-337f-4rfw"
]
}
CLEANSTART-2026-WX98343 (GHSA-JPCW-4WR7-C3VQ)
Vulnerability from cleanstart – Published: 2026-08-13 12:10 – Updated: 2026-09-18 11:59 – Source websitePackage grafana version 12.4.6-r0 fixes 4 vulnerabilities: ghsa-jpcw-4wr7-c3vq, ghsa-r277-6w6q-xmqw, ghsa-gcjh-h69q-9w9g, ghsa-259r-337f-4rfw
| URL | Type | |
|---|---|---|
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "grafana"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "12.4.6-r0"
}
],
"type": "ECOSYSTEM"
}
],
"versions": [
"12.4.6-r0"
]
}
],
"credits": [],
"database_specific": {},
"details": "Package grafana version 12.4.6-r0 fixes 4 vulnerabilities: ghsa-jpcw-4wr7-c3vq, ghsa-r277-6w6q-xmqw, ghsa-gcjh-h69q-9w9g, ghsa-259r-337f-4rfw",
"id": "CLEANSTART-2026-WX98343",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-08-13T12:10:09Z",
"references": [
{
"type": "WEB",
"url": "https://grafana.com"
}
],
"related": [],
"schema_version": "1.7.3",
"summary": "Security fixes in grafana 12.4.6-r0",
"upstream": [
"ghsa-jpcw-4wr7-c3vq",
"ghsa-r277-6w6q-xmqw",
"ghsa-gcjh-h69q-9w9g",
"ghsa-259r-337f-4rfw"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-WY48690 (GHSA-259R-337F-4RFW)
Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source websitePackage argo-cd version 3.4.7-r2 fixes 1 vulnerabilities: ghsa-259r-337f-4rfw
| URL | Type | |
|---|---|---|
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "argo-cd"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "3.4.7-r2"
}
],
"type": "ECOSYSTEM"
}
],
"versions": [
"3.4.7-r2"
]
}
],
"credits": [],
"database_specific": {},
"details": "Package argo-cd version 3.4.7-r2 fixes 1 vulnerabilities: ghsa-259r-337f-4rfw",
"id": "CLEANSTART-2026-WY48690",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-09-01T11:17:16Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/argoproj/argo-cd"
}
],
"related": [],
"schema_version": "1.7.3",
"summary": "Security fixes in argo-cd 3.4.7-r2",
"upstream": [
"ghsa-259r-337f-4rfw"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-XC36921 (CVE-2026-56852)
Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source websitePackage kubernetes-event-exporter version 1.5-r3 fixes 3 vulnerabilities: CVE-2026-56852, CVE-2026-41178, ghsa-259r-337f-4rfw
| URL | Type | |
|---|---|---|
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "kubernetes-event-exporter"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.5-r3"
}
],
"type": "ECOSYSTEM"
}
],
"versions": [
"1.5-r3"
]
}
],
"credits": [],
"database_specific": {},
"details": "Package kubernetes-event-exporter version 1.5-r3 fixes 3 vulnerabilities: CVE-2026-56852, CVE-2026-41178, ghsa-259r-337f-4rfw",
"id": "CLEANSTART-2026-XC36921",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-09-01T11:17:16Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/resmoio/kubernetes-event-exporter"
}
],
"related": [],
"schema_version": "1.7.3",
"summary": "Security fixes in kubernetes-event-exporter 1.5-r3",
"upstream": [
"CVE-2026-56852",
"CVE-2026-41178",
"ghsa-259r-337f-4rfw"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-XD35510 (CVE-2023-42821)
Vulnerability from cleanstart – Published: 2026-09-15 01:09 – Updated: 2026-09-18 11:59 – Source websiteMultiple security vulnerabilities affect the kube-metrics-adapter package. gRPC-Go is the Go language implementation of gRPC. See references for individual vulnerability details.
| URL | Type | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "kube-metrics-adapter"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.2.9-r4"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"credits": [],
"database_specific": {},
"details": "Multiple security vulnerabilities affect the kube-metrics-adapter package. gRPC-Go is the Go language implementation of gRPC. See references for individual vulnerability details.",
"id": "CLEANSTART-2026-XD35510",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-09-15T01:09:12.286403Z",
"references": [
{
"type": "ADVISORY",
"url": "https://github.com/cleanstart-dev/cleanstart-security-advisories/tree/main/advisories/2026/CLEANSTART-2026-XD35510.json"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2023-42821"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-33818"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39821"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-40890"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-40898"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-41178"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-46600"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-55677"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56853"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56858"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56859"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56860"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56862"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-73500"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-84303"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-84304"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-84445"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-259r-337f-4rfw"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-gcjh-h69q-9w9g"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-hrxh-6v49-42gf"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-42821"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33818"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39821"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-40890"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-40898"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41178"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46600"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-55677"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56853"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56858"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56859"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56860"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56862"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-73500"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84303"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84304"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84445"
}
],
"related": [],
"schema_version": "1.7.3",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"type": "CVSS_V3"
}
],
"summary": "gRPC-Go is the Go language implementation of gRPC",
"upstream": [
"CVE-2023-42821",
"CVE-2026-33818",
"CVE-2026-39821",
"CVE-2026-40890",
"CVE-2026-40898",
"CVE-2026-41178",
"CVE-2026-46600",
"CVE-2026-55677",
"CVE-2026-56853",
"CVE-2026-56858",
"CVE-2026-56859",
"CVE-2026-56860",
"CVE-2026-56862",
"CVE-2026-73500",
"CVE-2026-84303",
"CVE-2026-84304",
"CVE-2026-84445",
"ghsa-259r-337f-4rfw",
"ghsa-gcjh-h69q-9w9g",
"ghsa-hrxh-6v49-42gf"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-XK29798 (CVE-2026-56864)
Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source websitePackage ollama version 0.32.11-r1 fixes 3 vulnerabilities: CVE-2026-56864, CVE-2026-56865, ghsa-259r-337f-4rfw
| URL | Type | |
|---|---|---|
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "ollama"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.32.11-r1"
}
],
"type": "ECOSYSTEM"
}
],
"versions": [
"0.32.11-r1"
]
}
],
"credits": [],
"database_specific": {},
"details": "Package ollama version 0.32.11-r1 fixes 3 vulnerabilities: CVE-2026-56864, CVE-2026-56865, ghsa-259r-337f-4rfw",
"id": "CLEANSTART-2026-XK29798",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-09-01T11:17:16Z",
"references": [
{
"type": "WEB",
"url": "https://ollama.com"
}
],
"related": [],
"schema_version": "1.7.3",
"summary": "Security fixes in ollama 0.32.11-r1",
"upstream": [
"CVE-2026-56864",
"CVE-2026-56865",
"ghsa-259r-337f-4rfw"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-XT48985 (CVE-2026-50195)
Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source websitePackage rancher-agent version 2.12.11-r1 fixes 18 vulnerabilities: CVE-2026-50195, CVE-2026-53492, CVE-2026-53489, CVE-2026-46680, CVE-2026-53488...
| URL | Type | |
|---|---|---|
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "rancher-agent"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "2.12.11-r1"
}
],
"type": "ECOSYSTEM"
}
],
"versions": [
"2.12.11-r1"
]
}
],
"credits": [],
"database_specific": {},
"details": "Package rancher-agent version 2.12.11-r1 fixes 18 vulnerabilities: CVE-2026-50195, CVE-2026-53492, CVE-2026-53489, CVE-2026-46680, CVE-2026-53488...",
"id": "CLEANSTART-2026-XT48985",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-09-01T11:17:16Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/rancher/rancher"
}
],
"related": [],
"schema_version": "1.7.3",
"summary": "Security fixes in rancher-agent 2.12.11-r1",
"upstream": [
"CVE-2026-50195",
"CVE-2026-53492",
"CVE-2026-53489",
"CVE-2026-46680",
"CVE-2026-53488",
"CVE-2026-47262",
"ghsa-hrxh-6v49-42gf",
"CVE-2026-56864",
"CVE-2026-56865",
"CVE-2026-56852",
"CVE-2026-50163",
"CVE-2026-48978",
"CVE-2026-50151",
"CVE-2026-50162",
"ghsa-vh4v-2xq2-g5cg",
"ghsa-gcjh-h69q-9w9g",
"CVE-2026-41178",
"ghsa-259r-337f-4rfw"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-XV71690 (CVE-2026-53492)
Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source websitePackage rancher-fleet-agent version 0.14.8-r1 fixes 39 vulnerabilities: CVE-2026-53492, CVE-2026-50195, CVE-2026-53489, CVE-2026-46680, CVE-2026-53488...
| URL | Type | |
|---|---|---|
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "rancher-fleet-agent"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.14.8-r1"
}
],
"type": "ECOSYSTEM"
}
],
"versions": [
"0.14.8-r1"
]
}
],
"credits": [],
"database_specific": {},
"details": "Package rancher-fleet-agent version 0.14.8-r1 fixes 39 vulnerabilities: CVE-2026-53492, CVE-2026-50195, CVE-2026-53489, CVE-2026-46680, CVE-2026-53488...",
"id": "CLEANSTART-2026-XV71690",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-09-01T11:17:16Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/rancher/fleet"
}
],
"related": [],
"schema_version": "1.7.3",
"summary": "Security fixes in rancher-fleet-agent 0.14.8-r1",
"upstream": [
"CVE-2026-53492",
"CVE-2026-50195",
"CVE-2026-53489",
"CVE-2026-46680",
"CVE-2026-53488",
"CVE-2026-47262",
"CVE-2026-42508",
"CVE-2026-39835",
"CVE-2026-46598",
"CVE-2026-39828",
"CVE-2026-39829",
"CVE-2026-46597",
"CVE-2026-39830",
"CVE-2026-39831",
"CVE-2026-39832",
"CVE-2026-39833",
"CVE-2026-39834",
"CVE-2026-46595",
"CVE-2026-39827",
"CVE-2026-33186",
"ghsa-hrxh-6v49-42gf",
"CVE-2026-46600",
"CVE-2026-25681",
"CVE-2026-27136",
"CVE-2026-39821",
"CVE-2026-42502",
"CVE-2026-42506",
"CVE-2026-25680",
"CVE-2026-29181",
"CVE-2026-35469",
"CVE-2026-56852",
"CVE-2026-50163",
"CVE-2026-48978",
"CVE-2026-50151",
"CVE-2026-50162",
"ghsa-vh4v-2xq2-g5cg",
"CVE-2026-39824",
"CVE-2026-35206",
"ghsa-259r-337f-4rfw"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-XV99350 (CVE-2025-47912)
Vulnerability from cleanstart – Published: 2026-09-10 01:29 – Updated: 2026-09-18 11:59 – Source websiteMultiple security vulnerabilities affect the kyverno package. A malicious GOSUMDB was capable of serving arbitrary module content not contained within the transparency log. See references for individual vulnerability details.
| URL | Type | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "kyverno"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.17.2-r3"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"credits": [],
"database_specific": {},
"details": "Multiple security vulnerabilities affect the kyverno package. A malicious GOSUMDB was capable of serving arbitrary module content not contained within the transparency log. See references for individual vulnerability details.",
"id": "CLEANSTART-2026-XV99350",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-09-10T01:29:08.629807Z",
"references": [
{
"type": "ADVISORY",
"url": "https://github.com/cleanstart-dev/cleanstart-security-advisories/tree/main/advisories/2026/CLEANSTART-2026-XV99350.json"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-47912"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-58183"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-58185"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-58186"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-58187"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-58188"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-58189"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-61723"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-61724"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-61725"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-61729"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-24122"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-32952"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39395"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39984"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-48978"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-49478"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-49834"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-50151"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-50162"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-50163"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-54787"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56864"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56865"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-259r-337f-4rfw"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-gcjh-h69q-9w9g"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-hrxh-6v49-42gf"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-pmwq-pjrm-6p5r"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-vh4v-2xq2-g5cg"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47912"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58183"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58185"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58186"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58187"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58188"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58189"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61723"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61724"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61725"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61729"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-24122"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32952"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39395"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39984"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-48978"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-49478"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-49834"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-50151"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-50162"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-50163"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54787"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56864"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56865"
}
],
"related": [],
"schema_version": "1.7.3",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"type": "CVSS_V3"
}
],
"summary": "malicious GOSUMDB was capable of serving arbitrary module content not contained within the transparency log",
"upstream": [
"CVE-2025-47912",
"CVE-2025-58183",
"CVE-2025-58185",
"CVE-2025-58186",
"CVE-2025-58187",
"CVE-2025-58188",
"CVE-2025-58189",
"CVE-2025-61723",
"CVE-2025-61724",
"CVE-2025-61725",
"CVE-2025-61729",
"CVE-2026-24122",
"CVE-2026-32952",
"CVE-2026-39395",
"CVE-2026-39984",
"CVE-2026-48978",
"CVE-2026-49478",
"CVE-2026-49834",
"CVE-2026-50151",
"CVE-2026-50162",
"CVE-2026-50163",
"CVE-2026-54787",
"CVE-2026-56864",
"CVE-2026-56865",
"ghsa-259r-337f-4rfw",
"ghsa-gcjh-h69q-9w9g",
"ghsa-hrxh-6v49-42gf",
"ghsa-pmwq-pjrm-6p5r",
"ghsa-vh4v-2xq2-g5cg"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-YC27448 (CVE-2026-56860)
Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source websitePackage prometheus-redis-exporter-fips version 1.87.0-r1 fixes 8 vulnerabilities: CVE-2026-56860, CVE-2026-56858, CVE-2026-33818, CVE-2026-56853, CVE-2026-56859...
| URL | Type | |
|---|---|---|
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "prometheus-redis-exporter-fips"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.87.0-r1"
}
],
"type": "ECOSYSTEM"
}
],
"versions": [
"1.87.0-r1"
]
}
],
"credits": [],
"database_specific": {},
"details": "Package prometheus-redis-exporter-fips version 1.87.0-r1 fixes 8 vulnerabilities: CVE-2026-56860, CVE-2026-56858, CVE-2026-33818, CVE-2026-56853, CVE-2026-56859...",
"id": "CLEANSTART-2026-YC27448",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-09-01T11:17:16Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/oliver006/redis_exporter"
}
],
"related": [],
"schema_version": "1.7.3",
"summary": "Security fixes in prometheus-redis-exporter-fips 1.87.0-r1",
"upstream": [
"CVE-2026-56860",
"CVE-2026-56858",
"CVE-2026-33818",
"CVE-2026-56853",
"CVE-2026-56859",
"CVE-2026-56862",
"CVE-2026-39821",
"ghsa-259r-337f-4rfw"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-YI59826 (GHSA-HRXH-6V49-42GF)
Vulnerability from cleanstart – Published: 2026-08-13 12:10 – Updated: 2026-09-18 11:59 – Source websitePackage gitea version 1.26.4-r1 fixes 9 vulnerabilities: ghsa-hrxh-6v49-42gf, CVE-2026-56852, CVE-2026-71556, CVE-2026-71557, ghsa-259r-337f-4rfw...
| URL | Type | |
|---|---|---|
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "gitea"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.26.4-r1"
}
],
"type": "ECOSYSTEM"
}
],
"versions": [
"1.26.4-r1"
]
}
],
"credits": [],
"database_specific": {},
"details": "Package gitea version 1.26.4-r1 fixes 9 vulnerabilities: ghsa-hrxh-6v49-42gf, CVE-2026-56852, CVE-2026-71556, CVE-2026-71557, ghsa-259r-337f-4rfw...",
"id": "CLEANSTART-2026-YI59826",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-08-13T12:10:09Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/go-gitea/gitea"
}
],
"related": [],
"schema_version": "1.7.3",
"summary": "Security fixes in gitea 1.26.4-r1",
"upstream": [
"ghsa-hrxh-6v49-42gf",
"CVE-2026-56852",
"CVE-2026-71556",
"CVE-2026-71557",
"ghsa-259r-337f-4rfw",
"CVE-2026-46600",
"ghsa-3fxj-6jh8-hvhx",
"ghsa-9g5q-2w5x-hmxf",
"ghsa-rjr7-jggh-pgcp"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-YL93188 (CVE-2026-46602)
Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source websitePackage ollama version 0.32.11-r3 fixes 11 vulnerabilities: CVE-2026-46602, CVE-2026-33809, CVE-2026-33812, CVE-2026-33813, CVE-2026-46599...
| URL | Type | |
|---|---|---|
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "ollama"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.32.11-r3"
}
],
"type": "ECOSYSTEM"
}
],
"versions": [
"0.32.11-r3"
]
}
],
"credits": [],
"database_specific": {},
"details": "Package ollama version 0.32.11-r3 fixes 11 vulnerabilities: CVE-2026-46602, CVE-2026-33809, CVE-2026-33812, CVE-2026-33813, CVE-2026-46599...",
"id": "CLEANSTART-2026-YL93188",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-09-01T11:17:16Z",
"references": [
{
"type": "WEB",
"url": "https://ollama.com"
}
],
"related": [],
"schema_version": "1.7.3",
"summary": "Security fixes in ollama 0.32.11-r3",
"upstream": [
"CVE-2026-46602",
"CVE-2026-33809",
"CVE-2026-33812",
"CVE-2026-33813",
"CVE-2026-46599",
"CVE-2026-46601",
"CVE-2026-46604",
"CVE-2026-42500",
"CVE-2026-56864",
"CVE-2026-56865",
"ghsa-259r-337f-4rfw"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-YO86996 (CVE-2026-25680)
Vulnerability from cleanstart – Published: 2026-09-11 00:49 – Updated: 2026-09-18 11:59 – Source websiteMultiple security vulnerabilities affect the cadvisor package. Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. See references for individual vulnerability details.
| URL | Type | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "cadvisor"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.57.0-r6"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"credits": [],
"database_specific": {},
"details": "Multiple security vulnerabilities affect the cadvisor package. Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. See references for individual vulnerability details.",
"id": "CLEANSTART-2026-YO86996",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-09-11T00:49:41.696255Z",
"references": [
{
"type": "ADVISORY",
"url": "https://github.com/cleanstart-dev/cleanstart-security-advisories/tree/main/advisories/2026/CLEANSTART-2026-YO86996.json"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-25680"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-25681"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-27136"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-27145"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-29181"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-33186"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-33818"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39821"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39822"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39824"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39827"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39828"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39829"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39830"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39831"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39832"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39833"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39834"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39835"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-41579"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42502"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42504"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42505"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42506"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42507"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42508"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-46595"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-46597"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-46598"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-46600"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56852"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56853"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56855"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56858"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56859"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56860"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56862"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-78662"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-84303"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-84304"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-84445"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-259r-337f-4rfw"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-hrxh-6v49-42gf"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-mh2q-q3fh-2475"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-xjvp-4fhw-gc47"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25680"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25681"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27136"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27145"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-29181"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33186"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33818"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39821"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39822"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39824"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39827"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39828"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39829"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39830"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39831"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39832"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39833"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39834"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39835"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41579"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42502"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42504"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42505"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42506"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42507"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42508"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46595"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46597"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46598"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46600"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56852"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56853"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56855"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56858"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56859"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56860"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56862"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78662"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84303"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84304"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84445"
}
],
"related": [],
"schema_version": "1.7.3",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"type": "CVSS_V3"
}
],
"summary": "Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection",
"upstream": [
"CVE-2026-25680",
"CVE-2026-25681",
"CVE-2026-27136",
"CVE-2026-27145",
"CVE-2026-29181",
"CVE-2026-33186",
"CVE-2026-33818",
"CVE-2026-39821",
"CVE-2026-39822",
"CVE-2026-39824",
"CVE-2026-39827",
"CVE-2026-39828",
"CVE-2026-39829",
"CVE-2026-39830",
"CVE-2026-39831",
"CVE-2026-39832",
"CVE-2026-39833",
"CVE-2026-39834",
"CVE-2026-39835",
"CVE-2026-41579",
"CVE-2026-42502",
"CVE-2026-42504",
"CVE-2026-42505",
"CVE-2026-42506",
"CVE-2026-42507",
"CVE-2026-42508",
"CVE-2026-46595",
"CVE-2026-46597",
"CVE-2026-46598",
"CVE-2026-46600",
"CVE-2026-56852",
"CVE-2026-56853",
"CVE-2026-56855",
"CVE-2026-56858",
"CVE-2026-56859",
"CVE-2026-56860",
"CVE-2026-56862",
"CVE-2026-78662",
"CVE-2026-84303",
"CVE-2026-84304",
"CVE-2026-84445",
"ghsa-259r-337f-4rfw",
"ghsa-hrxh-6v49-42gf",
"ghsa-mh2q-q3fh-2475",
"ghsa-xjvp-4fhw-gc47"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-YQ04725 (CVE-2026-42508)
Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source websitePackage prometheus-pushgateway version 1.10.0-r3 fixes 35 vulnerabilities: CVE-2026-42508, CVE-2025-47914, CVE-2025-58181, CVE-2026-39835, CVE-2026-46598...
| URL | Type | |
|---|---|---|
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "prometheus-pushgateway"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.10.0-r3"
}
],
"type": "ECOSYSTEM"
}
],
"versions": [
"1.10.0-r3"
]
}
],
"credits": [],
"database_specific": {},
"details": "Package prometheus-pushgateway version 1.10.0-r3 fixes 35 vulnerabilities: CVE-2026-42508, CVE-2025-47914, CVE-2025-58181, CVE-2026-39835, CVE-2026-46598...",
"id": "CLEANSTART-2026-YQ04725",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-09-01T11:17:16Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/prometheus/pushgateway"
}
],
"related": [],
"schema_version": "1.7.3",
"summary": "Security fixes in prometheus-pushgateway 1.10.0-r3",
"upstream": [
"CVE-2026-42508",
"CVE-2025-47914",
"CVE-2025-58181",
"CVE-2026-39835",
"CVE-2026-46598",
"CVE-2026-39828",
"CVE-2025-22869",
"CVE-2025-47913",
"CVE-2026-39829",
"CVE-2026-46597",
"CVE-2024-45337",
"CVE-2026-39830",
"CVE-2026-39831",
"CVE-2026-39832",
"CVE-2026-39833",
"CVE-2026-39834",
"CVE-2026-46595",
"CVE-2026-39827",
"CVE-2026-46600",
"CVE-2025-22870",
"CVE-2024-45338",
"CVE-2026-25681",
"CVE-2026-27136",
"CVE-2026-33814",
"CVE-2026-39821",
"CVE-2025-22872",
"CVE-2025-47911",
"CVE-2025-58190",
"CVE-2026-42502",
"CVE-2026-42506",
"CVE-2026-25680",
"CVE-2026-42151",
"CVE-2026-44903",
"CVE-2026-42154",
"ghsa-259r-337f-4rfw"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-YQ30478 (CVE-2025-15558)
Vulnerability from cleanstart – Published: 2026-09-18 01:18 – Updated: 2026-09-18 11:59 – Source websiteMultiple security vulnerabilities affect the dynatrace-operator package. The source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for CVE-2026-46595. See references for individual vulnerability details.
| URL | Type | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "dynatrace-operator"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.8.1-r8"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"credits": [],
"database_specific": {},
"details": "Multiple security vulnerabilities affect the dynatrace-operator package. The source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for CVE-2026-46595. See references for individual vulnerability details.",
"id": "CLEANSTART-2026-YQ30478",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-09-18T01:18:28.963406Z",
"references": [
{
"type": "ADVISORY",
"url": "https://github.com/cleanstart-dev/cleanstart-security-advisories/tree/main/advisories/2026/CLEANSTART-2026-YQ30478.json"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-15558"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-33818"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39821"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39822"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-41178"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42504"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42505"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-46600"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56852"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56853"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56854"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56855"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56858"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56859"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56860"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56862"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56864"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56865"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-78662"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-84303"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-84304"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-84445"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-259r-337f-4rfw"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-hrxh-6v49-42gf"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-15558"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33818"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39821"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39822"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41178"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42504"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42505"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46600"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56852"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56853"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56854"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56855"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56858"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56859"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56860"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56862"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56864"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56865"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78662"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84303"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84304"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84445"
}
],
"related": [],
"schema_version": "1.7.3",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"type": "CVSS_V3"
}
],
"summary": "source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for CVE-2...",
"upstream": [
"CVE-2025-15558",
"CVE-2026-33818",
"CVE-2026-39821",
"CVE-2026-39822",
"CVE-2026-41178",
"CVE-2026-42504",
"CVE-2026-42505",
"CVE-2026-46600",
"CVE-2026-56852",
"CVE-2026-56853",
"CVE-2026-56854",
"CVE-2026-56855",
"CVE-2026-56858",
"CVE-2026-56859",
"CVE-2026-56860",
"CVE-2026-56862",
"CVE-2026-56864",
"CVE-2026-56865",
"CVE-2026-78662",
"CVE-2026-84303",
"CVE-2026-84304",
"CVE-2026-84445",
"ghsa-259r-337f-4rfw",
"ghsa-hrxh-6v49-42gf"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-YR40466 (CVE-2026-53713)
Vulnerability from cleanstart – Published: 2026-08-13 12:10 – Updated: 2026-09-18 11:59 – Source websitePackage tigera-operator version 1.39.3-r1 fixes 17 vulnerabilities: CVE-2026-53713, CVE-2026-53714, CVE-2026-53715, CVE-2026-53716, CVE-2026-53717...
| URL | Type | |
|---|---|---|
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "tigera-operator"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.39.3-r1"
}
],
"type": "ECOSYSTEM"
}
],
"versions": [
"1.39.3-r1"
]
}
],
"credits": [],
"database_specific": {},
"details": "Package tigera-operator version 1.39.3-r1 fixes 17 vulnerabilities: CVE-2026-53713, CVE-2026-53714, CVE-2026-53715, CVE-2026-53716, CVE-2026-53717...",
"id": "CLEANSTART-2026-YR40466",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-08-13T12:10:09Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/tigera/operator"
}
],
"related": [],
"schema_version": "1.7.3",
"summary": "Security fixes in tigera-operator 1.39.3-r1",
"upstream": [
"CVE-2026-53713",
"CVE-2026-53714",
"CVE-2026-53715",
"CVE-2026-53716",
"CVE-2026-53717",
"CVE-2026-53718",
"CVE-2026-53719",
"CVE-2026-22771",
"ghsa-wcrf-9vrr-854f",
"ghsa-22xc-xg2r-9j7v",
"ghsa-8fv2-88gg-hm7q",
"ghsa-cxpq-8v7q-cg56",
"ghsa-fcrp-7gc2-93g7",
"ghsa-h7pq-86h8-rp5x",
"ghsa-m2v6-2jmh-4c68",
"ghsa-xrwg-mqj6-6m22",
"ghsa-259r-337f-4rfw"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-YS01797 (CVE-2026-27145)
Vulnerability from cleanstart – Published: 2026-09-10 02:14 – Updated: 2026-09-18 11:59 – Source websiteMultiple security vulnerabilities affect the calico package. The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. See references for individual vulnerability details.
| URL | Type | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "calico"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "3.30.7-r7"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"credits": [],
"database_specific": {},
"details": "Multiple security vulnerabilities affect the calico package. The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. See references for individual vulnerability details.",
"id": "CLEANSTART-2026-YS01797",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-09-10T02:14:45.873622Z",
"references": [
{
"type": "ADVISORY",
"url": "https://github.com/cleanstart-dev/cleanstart-security-advisories/tree/main/advisories/2026/CLEANSTART-2026-YS01797.json"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-27145"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-29181"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-32280"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-32281"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-32282"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-32283"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-32288"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-32289"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-33186"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-33810"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-33811"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-33814"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-33818"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39820"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39821"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39823"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39825"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39826"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39827"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39828"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39829"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39830"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39831"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39832"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39833"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39834"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39835"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39836"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39883"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-41178"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42499"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42504"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42507"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42508"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-46595"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-46597"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-46598"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-46600"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56853"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56858"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56859"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56860"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56862"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-73500"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-259r-337f-4rfw"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-gcjh-h69q-9w9g"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-hrxh-6v49-42gf"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-p77j-4mvh-x3m3"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27145"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-29181"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32280"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32281"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32282"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32283"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32288"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32289"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33186"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33810"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33811"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33814"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33818"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39820"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39821"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39823"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39825"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39826"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39827"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39828"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39829"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39830"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39831"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39832"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39833"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39834"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39835"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39836"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39883"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41178"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42499"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42504"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42507"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42508"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46595"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46597"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46598"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46600"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56853"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56858"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56859"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56860"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56862"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-73500"
}
],
"related": [],
"schema_version": "1.7.3",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"type": "CVSS_V3"
}
],
"summary": "ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label",
"upstream": [
"CVE-2026-27145",
"CVE-2026-29181",
"CVE-2026-32280",
"CVE-2026-32281",
"CVE-2026-32282",
"CVE-2026-32283",
"CVE-2026-32288",
"CVE-2026-32289",
"CVE-2026-33186",
"CVE-2026-33810",
"CVE-2026-33811",
"CVE-2026-33814",
"CVE-2026-33818",
"CVE-2026-39820",
"CVE-2026-39821",
"CVE-2026-39823",
"CVE-2026-39825",
"CVE-2026-39826",
"CVE-2026-39827",
"CVE-2026-39828",
"CVE-2026-39829",
"CVE-2026-39830",
"CVE-2026-39831",
"CVE-2026-39832",
"CVE-2026-39833",
"CVE-2026-39834",
"CVE-2026-39835",
"CVE-2026-39836",
"CVE-2026-39883",
"CVE-2026-41178",
"CVE-2026-42499",
"CVE-2026-42504",
"CVE-2026-42507",
"CVE-2026-42508",
"CVE-2026-46595",
"CVE-2026-46597",
"CVE-2026-46598",
"CVE-2026-46600",
"CVE-2026-56853",
"CVE-2026-56858",
"CVE-2026-56859",
"CVE-2026-56860",
"CVE-2026-56862",
"CVE-2026-73500",
"ghsa-259r-337f-4rfw",
"ghsa-gcjh-h69q-9w9g",
"ghsa-hrxh-6v49-42gf",
"ghsa-p77j-4mvh-x3m3"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-YZ14479 (CVE-2026-25681)
Vulnerability from cleanstart – Published: 2026-09-18 00:47 – Updated: 2026-09-18 11:59 – Source websiteMultiple security vulnerabilities affect the dex package. gRPC-Go is the Go language implementation of gRPC. See references for individual vulnerability details.
| URL | Type | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "dex"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "2.42.1-r6"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"credits": [],
"database_specific": {},
"details": "Multiple security vulnerabilities affect the dex package. gRPC-Go is the Go language implementation of gRPC. See references for individual vulnerability details.",
"id": "CLEANSTART-2026-YZ14479",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-09-18T00:47:58.234272Z",
"references": [
{
"type": "ADVISORY",
"url": "https://github.com/cleanstart-dev/cleanstart-security-advisories/tree/main/advisories/2026/CLEANSTART-2026-YZ14479.json"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-25681"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-27136"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-29181"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-32952"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-33487"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-34986"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39824"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39828"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39829"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39830"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39831"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39832"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39833"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39834"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39835"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-41178"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42508"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-46595"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-46598"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56852"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56855"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56864"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56865"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-78662"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-84303"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-84304"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-84445"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-259r-337f-4rfw"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-fw7p-63qq-7hpr"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-hrxh-6v49-42gf"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25681"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27136"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-29181"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32952"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33487"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-34986"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39824"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39828"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39829"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39830"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39831"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39832"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39833"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39834"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39835"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41178"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42508"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46595"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46598"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56852"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56855"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56864"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56865"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78662"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84303"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84304"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84445"
}
],
"related": [],
"schema_version": "1.7.3",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"type": "CVSS_V3"
}
],
"summary": "gRPC-Go is the Go language implementation of gRPC",
"upstream": [
"CVE-2026-25681",
"CVE-2026-27136",
"CVE-2026-29181",
"CVE-2026-32952",
"CVE-2026-33487",
"CVE-2026-34986",
"CVE-2026-39824",
"CVE-2026-39828",
"CVE-2026-39829",
"CVE-2026-39830",
"CVE-2026-39831",
"CVE-2026-39832",
"CVE-2026-39833",
"CVE-2026-39834",
"CVE-2026-39835",
"CVE-2026-41178",
"CVE-2026-42508",
"CVE-2026-46595",
"CVE-2026-46598",
"CVE-2026-56852",
"CVE-2026-56855",
"CVE-2026-56864",
"CVE-2026-56865",
"CVE-2026-78662",
"CVE-2026-84303",
"CVE-2026-84304",
"CVE-2026-84445",
"ghsa-259r-337f-4rfw",
"ghsa-fw7p-63qq-7hpr",
"ghsa-hrxh-6v49-42gf"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-ZB65236 (CVE-2026-41178)
Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source websitePackage newrelic-infrastructure-agent version 1.78.1-r1 fixes 2 vulnerabilities: CVE-2026-41178, ghsa-259r-337f-4rfw
| URL | Type | |
|---|---|---|
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "newrelic-infrastructure-agent"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.78.1-r1"
}
],
"type": "ECOSYSTEM"
}
],
"versions": [
"1.78.1-r1"
]
}
],
"credits": [],
"database_specific": {},
"details": "Package newrelic-infrastructure-agent version 1.78.1-r1 fixes 2 vulnerabilities: CVE-2026-41178, ghsa-259r-337f-4rfw",
"id": "CLEANSTART-2026-ZB65236",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-09-01T11:17:16Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/newrelic/infrastructure-agent"
}
],
"related": [],
"schema_version": "1.7.3",
"summary": "Security fixes in newrelic-infrastructure-agent 1.78.1-r1",
"upstream": [
"CVE-2026-41178",
"ghsa-259r-337f-4rfw"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-ZB75097 (GHSA-259R-337F-4RFW)
Vulnerability from cleanstart – Published: 2026-08-13 12:10 – Updated: 2026-09-18 11:59 – Source websitePackage cortex version 1.20.1-r3 fixes 5 vulnerabilities: ghsa-259r-337f-4rfw, ghsa-3fxj-6jh8-hvhx, ghsa-9g5q-2w5x-hmxf, ghsa-rjr7-jggh-pgcp, CVE-2026-41178
| URL | Type | |
|---|---|---|
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "cortex"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.20.1-r3"
}
],
"type": "ECOSYSTEM"
}
],
"versions": [
"1.20.1-r3"
]
}
],
"credits": [],
"database_specific": {},
"details": "Package cortex version 1.20.1-r3 fixes 5 vulnerabilities: ghsa-259r-337f-4rfw, ghsa-3fxj-6jh8-hvhx, ghsa-9g5q-2w5x-hmxf, ghsa-rjr7-jggh-pgcp, CVE-2026-41178",
"id": "CLEANSTART-2026-ZB75097",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-08-13T12:10:09Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/cortexproject/cortex"
}
],
"related": [],
"schema_version": "1.7.3",
"summary": "Security fixes in cortex 1.20.1-r3",
"upstream": [
"ghsa-259r-337f-4rfw",
"ghsa-3fxj-6jh8-hvhx",
"ghsa-9g5q-2w5x-hmxf",
"ghsa-rjr7-jggh-pgcp",
"CVE-2026-41178"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-ZG01398 (CVE-2026-33818)
Vulnerability from cleanstart – Published: 2026-09-17 01:07 – Updated: 2026-09-18 11:59 – Source websiteMultiple security vulnerabilities affect the terraform package. gRPC-Go is the Go language implementation of gRPC. See references for individual vulnerability details.
| URL | Type | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "terraform"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.16.0-r2"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"credits": [],
"database_specific": {},
"details": "Multiple security vulnerabilities affect the terraform package. gRPC-Go is the Go language implementation of gRPC. See references for individual vulnerability details.",
"id": "CLEANSTART-2026-ZG01398",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-09-17T01:07:19.033250Z",
"references": [
{
"type": "ADVISORY",
"url": "https://github.com/cleanstart-dev/cleanstart-security-advisories/tree/main/advisories/2026/CLEANSTART-2026-ZG01398.json"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-33818"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39821"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-41178"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-4660"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-46600"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56853"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56855"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56858"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56859"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56860"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56862"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56864"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56865"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-78662"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-84303"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-84304"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-84445"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-259r-337f-4rfw"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33818"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39821"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41178"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-4660"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46600"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56853"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56855"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56858"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56859"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56860"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56862"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56864"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56865"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78662"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84303"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84304"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84445"
}
],
"related": [],
"schema_version": "1.7.3",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"type": "CVSS_V3"
}
],
"summary": "gRPC-Go is the Go language implementation of gRPC",
"upstream": [
"CVE-2026-33818",
"CVE-2026-39821",
"CVE-2026-41178",
"CVE-2026-4660",
"CVE-2026-46600",
"CVE-2026-56853",
"CVE-2026-56855",
"CVE-2026-56858",
"CVE-2026-56859",
"CVE-2026-56860",
"CVE-2026-56862",
"CVE-2026-56864",
"CVE-2026-56865",
"CVE-2026-78662",
"CVE-2026-84303",
"CVE-2026-84304",
"CVE-2026-84445",
"ghsa-259r-337f-4rfw"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-ZG59988 (CVE-2026-39821)
Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source websitePackage temporal-server version 1.29.7-r1 fixes 15 vulnerabilities: CVE-2026-39821, CVE-2026-33818, CVE-2026-46600, CVE-2026-56853, CVE-2026-56858...
| URL | Type | |
|---|---|---|
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "temporal-server"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.29.7-r1"
}
],
"type": "ECOSYSTEM"
}
],
"versions": [
"1.29.7-r1"
]
}
],
"credits": [],
"database_specific": {},
"details": "Package temporal-server version 1.29.7-r1 fixes 15 vulnerabilities: CVE-2026-39821, CVE-2026-33818, CVE-2026-46600, CVE-2026-56853, CVE-2026-56858...",
"id": "CLEANSTART-2026-ZG59988",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-09-01T11:17:16Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/temporalio/temporal"
}
],
"related": [],
"schema_version": "1.7.3",
"summary": "Security fixes in temporal-server 1.29.7-r1",
"upstream": [
"CVE-2026-39821",
"CVE-2026-33818",
"CVE-2026-46600",
"CVE-2026-56853",
"CVE-2026-56858",
"CVE-2026-56859",
"CVE-2026-56860",
"CVE-2026-56862",
"CVE-2026-5724",
"CVE-2025-14987",
"CVE-2025-14986",
"CVE-2026-5199",
"ghsa-hrxh-6v49-42gf",
"ghsa-259r-337f-4rfw",
"CVE-2026-41178"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-ZI93173 (CVE-2024-53259)
Vulnerability from cleanstart – Published: 2026-09-10 01:32 – Updated: 2026-09-18 11:59 – Source websiteMultiple security vulnerabilities affect the kubernetes-dns-node-cache package. The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. See references for individual vulnerability details.
| URL | Type | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "kubernetes-dns-node-cache"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.26.8-r5"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"credits": [],
"database_specific": {},
"details": "Multiple security vulnerabilities affect the kubernetes-dns-node-cache package. The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. See references for individual vulnerability details.",
"id": "CLEANSTART-2026-ZI93173",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-09-10T01:32:39.433553Z",
"references": [
{
"type": "ADVISORY",
"url": "https://github.com/cleanstart-dev/cleanstart-security-advisories/tree/main/advisories/2026/CLEANSTART-2026-ZI93173.json"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2024-53259"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-47950"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-58063"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-59530"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-64702"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2025-68151"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-26017"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-26018"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-32934"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-32936"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-33190"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-33489"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-33818"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-35579"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39821"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-39822"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-40898"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42504"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-42505"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-46600"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56852"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56853"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56858"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56859"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56860"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56862"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56864"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/CVE-2026-56865"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-259r-337f-4rfw"
},
{
"type": "WEB",
"url": "https://osv.dev/vulnerability/ghsa-hrxh-6v49-42gf"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53259"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47950"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58063"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-59530"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-64702"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-68151"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-26017"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-26018"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32934"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32936"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33190"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33489"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33818"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-35579"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39821"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39822"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-40898"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42504"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42505"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46600"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56852"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56853"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56858"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56859"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56860"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56862"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56864"
},
{
"type": "WEB",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56865"
}
],
"related": [],
"schema_version": "1.7.3",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"type": "CVSS_V3"
}
],
"summary": "ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label",
"upstream": [
"CVE-2024-53259",
"CVE-2025-47950",
"CVE-2025-58063",
"CVE-2025-59530",
"CVE-2025-64702",
"CVE-2025-68151",
"CVE-2026-26017",
"CVE-2026-26018",
"CVE-2026-32934",
"CVE-2026-32936",
"CVE-2026-33190",
"CVE-2026-33489",
"CVE-2026-33818",
"CVE-2026-35579",
"CVE-2026-39821",
"CVE-2026-39822",
"CVE-2026-40898",
"CVE-2026-42504",
"CVE-2026-42505",
"CVE-2026-46600",
"CVE-2026-56852",
"CVE-2026-56853",
"CVE-2026-56858",
"CVE-2026-56859",
"CVE-2026-56860",
"CVE-2026-56862",
"CVE-2026-56864",
"CVE-2026-56865",
"ghsa-259r-337f-4rfw",
"ghsa-hrxh-6v49-42gf"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-ZS03179 (GHSA-259R-337F-4RFW)
Vulnerability from cleanstart – Published: 2026-08-13 12:10 – Updated: 2026-09-18 11:59 – Source websitePackage opentelemetry-collector-contrib version 0.153.0-r3 fixes 1 vulnerabilities: ghsa-259r-337f-4rfw
| URL | Type | |
|---|---|---|
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "opentelemetry-collector-contrib"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.153.0-r3"
}
],
"type": "ECOSYSTEM"
}
],
"versions": [
"0.153.0-r3"
]
}
],
"credits": [],
"database_specific": {},
"details": "Package opentelemetry-collector-contrib version 0.153.0-r3 fixes 1 vulnerabilities: ghsa-259r-337f-4rfw",
"id": "CLEANSTART-2026-ZS03179",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-08-13T12:10:09Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/open-telemetry/opentelemetry-collector-contrib"
}
],
"related": [],
"schema_version": "1.7.3",
"summary": "Security fixes in opentelemetry-collector-contrib 0.153.0-r3",
"upstream": [
"ghsa-259r-337f-4rfw"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-ZU67009 (CVE-2026-53492)
Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source websitePackage rancher-agent version 2.14.3-r0 fixes 17 vulnerabilities: CVE-2026-53492, CVE-2026-50195, CVE-2026-46680, CVE-2026-53488, ghsa-hrxh-6v49-42gf...
| URL | Type | |
|---|---|---|
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "rancher-agent"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "2.14.3-r0"
}
],
"type": "ECOSYSTEM"
}
],
"versions": [
"2.14.3-r0"
]
}
],
"credits": [],
"database_specific": {},
"details": "Package rancher-agent version 2.14.3-r0 fixes 17 vulnerabilities: CVE-2026-53492, CVE-2026-50195, CVE-2026-46680, CVE-2026-53488, ghsa-hrxh-6v49-42gf...",
"id": "CLEANSTART-2026-ZU67009",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-09-01T11:17:16Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/rancher/rancher"
}
],
"related": [],
"schema_version": "1.7.3",
"summary": "Security fixes in rancher-agent 2.14.3-r0",
"upstream": [
"CVE-2026-53492",
"CVE-2026-50195",
"CVE-2026-46680",
"CVE-2026-53488",
"ghsa-hrxh-6v49-42gf",
"CVE-2026-56864",
"CVE-2026-56865",
"CVE-2026-48978",
"CVE-2026-50163",
"CVE-2026-50151",
"CVE-2026-53489",
"ghsa-gcjh-h69q-9w9g",
"CVE-2026-47262",
"CVE-2026-41178",
"CVE-2026-50162",
"ghsa-vh4v-2xq2-g5cg",
"ghsa-259r-337f-4rfw"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CLEANSTART-2026-ZX66437 (GHSA-259R-337F-4RFW)
Vulnerability from cleanstart – Published: 2026-09-01 11:17 – Updated: 2026-09-18 11:59 – Source websitePackage cadvisor version 0.60.5-r0 fixes 2 vulnerabilities: ghsa-259r-337f-4rfw, ghsa-hrxh-6v49-42gf
| URL | Type | |
|---|---|---|
{
"affected": [
{
"package": {
"ecosystem": "CleanStart",
"name": "cadvisor"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.60.5-r0"
}
],
"type": "ECOSYSTEM"
}
],
"versions": [
"0.60.5-r0"
]
}
],
"credits": [],
"database_specific": {},
"details": "Package cadvisor version 0.60.5-r0 fixes 2 vulnerabilities: ghsa-259r-337f-4rfw, ghsa-hrxh-6v49-42gf",
"id": "CLEANSTART-2026-ZX66437",
"modified": "2026-09-18T11:59:01.768079Z",
"published": "2026-09-01T11:17:16Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/google/cadvisor"
}
],
"related": [],
"schema_version": "1.7.3",
"summary": "Security fixes in cadvisor 0.60.5-r0",
"upstream": [
"ghsa-259r-337f-4rfw",
"ghsa-hrxh-6v49-42gf"
],
"withdrawn": "2026-09-18T11:59:01.768079Z"
}
CVE-2026-63209 (GCVE-0-2026-63209)
Vulnerability from cvelistv5 – Published: 2026-09-29 14:58 – Updated: 2026-09-29 16:32| URL | Tags |
|---|---|
| https://github.com/klauspost/compress/security/ad… | x_refsource_CONFIRM |
| https://github.com/klauspost/compress/commit/5392… | x_refsource_MISC |
| https://github.com/klauspost/compress/releases/ta… | x_refsource_MISC |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-63209",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-29T16:31:39.668233Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-29T16:32:32.677Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"references": [
{
"tags": [
"exploit"
],
"url": "https://github.com/klauspost/compress/security/advisories/GHSA-259r-337f-4rfw"
}
],
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "compress",
"vendor": "klauspost",
"versions": [
{
"status": "affected",
"version": "\u003c 1.18.7"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "compress provides various compression algorithms. Prior to version 1.18.7, a signed integer overflow vulnerability in s2.NewDict() allows an attacker to bypass repeat index validation by supplying a dictionary with a uvarint-encoded repeat value exceeding MaxInt64. When Dict.Encode() is subsequently called, the overflowed negative repeat value causes an out-of-bounds memory access via unsafe.Pointer arithmetic, crashing the process with SIGSEGV. This issue has been patched in version 1.18.7."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 7.5,
"baseSeverity": "HIGH",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-190",
"description": "CWE-190: Integer Overflow or Wraparound",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-787",
"description": "CWE-787: Out-of-bounds Write",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-29T14:58:53.366Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/klauspost/compress/security/advisories/GHSA-259r-337f-4rfw",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/klauspost/compress/security/advisories/GHSA-259r-337f-4rfw"
},
{
"name": "https://github.com/klauspost/compress/commit/539243b8823ee8f03e49969823d57c348c917536",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/klauspost/compress/commit/539243b8823ee8f03e49969823d57c348c917536"
},
{
"name": "https://github.com/klauspost/compress/releases/tag/v1.18.7",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/klauspost/compress/releases/tag/v1.18.7"
}
],
"source": {
"advisory": "GHSA-259r-337f-4rfw",
"discovery": "UNKNOWN"
},
"title": "Integer Overflow or Wraparound and Out-of-bounds Write in compress"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2026-63209",
"datePublished": "2026-09-29T14:58:53.366Z",
"dateReserved": "2026-07-15T22:19:06.906Z",
"dateUpdated": "2026-09-29T16:32:32.677Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}