{ "version": "2.1.0", "$schema": "https://raw.githubusercontent.com/oasis-tcs/sarif-spec/main/sarif-2.1/schema/sarif-schema-2.1.0.json", "runs": [ { "tool": { "driver": { "fullName": "Trivy Vulnerability Scanner", "informationUri": "https://github.com/aquasecurity/trivy", "name": "Trivy", "rules": [ { "id": "CVE-2026-53615", "name": "OsPackageVulnerability", "shortDescription": { "text": "[Integer Overflow or Wraparound in libblkid/src/partitions/dos.c]" }, "fullDescription": { "text": "Package updates are available for Amazon Linux 2023 that fix the following vulnerabilities:\nCVE-2026-53615:\n\tInteger Overflow or Wraparound in libblkid/src/partitions/dos.c\n" }, "defaultConfiguration": { "level": "error" }, "helpUri": "https://avd.aquasec.com/nvd/cve-2026-53615", "help": { "text": "Vulnerability CVE-2026-53615\nSeverity: HIGH\nPackage: util-linux\nFixed Version: \nLink: [CVE-2026-53615](https://avd.aquasec.com/nvd/cve-2026-53615)\nPackage updates are available for Amazon Linux 2023 that fix the following vulnerabilities:\nCVE-2026-53615:\n\tInteger Overflow or Wraparound in libblkid/src/partitions/dos.c\n", "markdown": "**Vulnerability CVE-2026-53615**\n| Severity | Package | Fixed Version | Link |\n| --- | --- | --- | --- |\n|HIGH|util-linux||[CVE-2026-53615](https://avd.aquasec.com/nvd/cve-2026-53615)|\n\nPackage updates are available for Amazon Linux 2023 that fix the following vulnerabilities:\nCVE-2026-53615:\n\tInteger Overflow or Wraparound in libblkid/src/partitions/dos.c\n" }, "properties": { "precision": "very-high", "security-severity": "8.0", "tags": [ "vulnerability", "security", "HIGH" ] } }, { "id": "CVE-2026-12064", "name": "OsPackageVulnerability", "shortDescription": { "text": "curl: curl: SSH host verification bypass when using schemeless URLs with SFTP/SCP" }, "fullDescription": { "text": "When a user invokes curl using a schemeless URL combined with\n`--proto-default` sftp (or scp), a disconnect occurs between the tool layer\nand libcurl. The tool layer incorrectly infers the URL scheme, which\nerroneously bypasses the initialization of critical SSH security options like\nCURLOPT_SSH_HOST_PUBLIC_KEY_SHA256 and CURLOPT_SSH_KNOWNHOSTS. Conversely, the\nlibcurl runtime successfully honors CURLOPT_DEFAULT_PROTOCOL and establishes\nthe connection via SFTP/SCP as specified. Because the tool layer skipped the\nsecurity configuration, these SSH host verification options are silently\nomitted, causing curl to connect to an unverified SSH remote host without\nthrowing an error." }, "defaultConfiguration": { "level": "error" }, "helpUri": "https://avd.aquasec.com/nvd/cve-2026-12064", "help": { "text": "Vulnerability CVE-2026-12064\nSeverity: HIGH\nPackage: libcurl4t64\nFixed Version: \nLink: [CVE-2026-12064](https://avd.aquasec.com/nvd/cve-2026-12064)\nWhen a user invokes curl using a schemeless URL combined with\n`--proto-default` sftp (or scp), a disconnect occurs between the tool layer\nand libcurl. The tool layer incorrectly infers the URL scheme, which\nerroneously bypasses the initialization of critical SSH security options like\nCURLOPT_SSH_HOST_PUBLIC_KEY_SHA256 and CURLOPT_SSH_KNOWNHOSTS. Conversely, the\nlibcurl runtime successfully honors CURLOPT_DEFAULT_PROTOCOL and establishes\nthe connection via SFTP/SCP as specified. Because the tool layer skipped the\nsecurity configuration, these SSH host verification options are silently\nomitted, causing curl to connect to an unverified SSH remote host without\nthrowing an error.", "markdown": "**Vulnerability CVE-2026-12064**\n| Severity | Package | Fixed Version | Link |\n| --- | --- | --- | --- |\n|HIGH|libcurl4t64||[CVE-2026-12064](https://avd.aquasec.com/nvd/cve-2026-12064)|\n\nWhen a user invokes curl using a schemeless URL combined with\n`--proto-default` sftp (or scp), a disconnect occurs between the tool layer\nand libcurl. The tool layer incorrectly infers the URL scheme, which\nerroneously bypasses the initialization of critical SSH security options like\nCURLOPT_SSH_HOST_PUBLIC_KEY_SHA256 and CURLOPT_SSH_KNOWNHOSTS. Conversely, the\nlibcurl runtime successfully honors CURLOPT_DEFAULT_PROTOCOL and establishes\nthe connection via SFTP/SCP as specified. Because the tool layer skipped the\nsecurity configuration, these SSH host verification options are silently\nomitted, causing curl to connect to an unverified SSH remote host without\nthrowing an error." }, "properties": { "precision": "very-high", "security-severity": "8.0", "tags": [ "vulnerability", "security", "HIGH" ] } }, { "id": "CVE-2026-8286", "name": "OsPackageVulnerability", "shortDescription": { "text": "curl: curl: Insecure connection establishment due to TLS configuration mismatch" }, "fullDescription": { "text": "A vulnerability exists where a new transfer that uses STARTTLS to upgrade the\nconnection might reuse an existing live connection even though the TLS\nconfiguration mismatches so it should not." }, "defaultConfiguration": { "level": "error" }, "helpUri": "https://avd.aquasec.com/nvd/cve-2026-8286", "help": { "text": "Vulnerability CVE-2026-8286\nSeverity: HIGH\nPackage: libcurl4t64\nFixed Version: \nLink: [CVE-2026-8286](https://avd.aquasec.com/nvd/cve-2026-8286)\nA vulnerability exists where a new transfer that uses STARTTLS to upgrade the\nconnection might reuse an existing live connection even though the TLS\nconfiguration mismatches so it should not.", "markdown": "**Vulnerability CVE-2026-8286**\n| Severity | Package | Fixed Version | Link |\n| --- | --- | --- | --- |\n|HIGH|libcurl4t64||[CVE-2026-8286](https://avd.aquasec.com/nvd/cve-2026-8286)|\n\nA vulnerability exists where a new transfer that uses STARTTLS to upgrade the\nconnection might reuse an existing live connection even though the TLS\nconfiguration mismatches so it should not." }, "properties": { "precision": "very-high", "security-severity": "8.0", "tags": [ "vulnerability", "security", "HIGH" ] } }, { "id": "CVE-2026-8927", "name": "OsPackageVulnerability", "shortDescription": { "text": "curl: Information disclosure due to uncleared proxy authentication state" }, "fullDescription": { "text": "When reusing a libcurl handle for sequential transfers driven by\nenvironment-variable proxy configuration, libcurl fails to clear the proxy\nauthentication state between requests. Specifically, if the initial transfer\nauthenticates against `proxyA` using Digest auth, a subsequent transfer routed\nthrough `proxyB` erroneously leaks the `Proxy-Authorization:` header intended\nsolely for `proxyA`." }, "defaultConfiguration": { "level": "error" }, "helpUri": "https://avd.aquasec.com/nvd/cve-2026-8927", "help": { "text": "Vulnerability CVE-2026-8927\nSeverity: HIGH\nPackage: libcurl4t64\nFixed Version: \nLink: [CVE-2026-8927](https://avd.aquasec.com/nvd/cve-2026-8927)\nWhen reusing a libcurl handle for sequential transfers driven by\nenvironment-variable proxy configuration, libcurl fails to clear the proxy\nauthentication state between requests. Specifically, if the initial transfer\nauthenticates against `proxyA` using Digest auth, a subsequent transfer routed\nthrough `proxyB` erroneously leaks the `Proxy-Authorization:` header intended\nsolely for `proxyA`.", "markdown": "**Vulnerability CVE-2026-8927**\n| Severity | Package | Fixed Version | Link |\n| --- | --- | --- | --- |\n|HIGH|libcurl4t64||[CVE-2026-8927](https://avd.aquasec.com/nvd/cve-2026-8927)|\n\nWhen reusing a libcurl handle for sequential transfers driven by\nenvironment-variable proxy configuration, libcurl fails to clear the proxy\nauthentication state between requests. Specifically, if the initial transfer\nauthenticates against `proxyA` using Digest auth, a subsequent transfer routed\nthrough `proxyB` erroneously leaks the `Proxy-Authorization:` header intended\nsolely for `proxyA`." }, "properties": { "precision": "very-high", "security-severity": "8.0", "tags": [ "vulnerability", "security", "HIGH" ] } }, { "id": "CVE-2026-8932", "name": "OsPackageVulnerability", "shortDescription": { "text": "libcurl: libcurl: Security feature bypass due to improper mTLS connection reuse" }, "fullDescription": { "text": "libcurl would reuse a previously created connection even when some mTLS config\nrelated option had been changed that should have prohibited reuse.\n\nlibcurl keeps previously used connections in a connection pool for subsequent\ntransfers to reuse if one of them matches the setup. However, some TLS\nsettings related to client certificates were left out from the configuration\nmatch checks, making them match too easily. In particular options related to\nthe private key." }, "defaultConfiguration": { "level": "error" }, "helpUri": "https://avd.aquasec.com/nvd/cve-2026-8932", "help": { "text": "Vulnerability CVE-2026-8932\nSeverity: HIGH\nPackage: libcurl4t64\nFixed Version: \nLink: [CVE-2026-8932](https://avd.aquasec.com/nvd/cve-2026-8932)\nlibcurl would reuse a previously created connection even when some mTLS config\nrelated option had been changed that should have prohibited reuse.\n\nlibcurl keeps previously used connections in a connection pool for subsequent\ntransfers to reuse if one of them matches the setup. However, some TLS\nsettings related to client certificates were left out from the configuration\nmatch checks, making them match too easily. In particular options related to\nthe private key.", "markdown": "**Vulnerability CVE-2026-8932**\n| Severity | Package | Fixed Version | Link |\n| --- | --- | --- | --- |\n|HIGH|libcurl4t64||[CVE-2026-8932](https://avd.aquasec.com/nvd/cve-2026-8932)|\n\nlibcurl would reuse a previously created connection even when some mTLS config\nrelated option had been changed that should have prohibited reuse.\n\nlibcurl keeps previously used connections in a connection pool for subsequent\ntransfers to reuse if one of them matches the setup. However, some TLS\nsettings related to client certificates were left out from the configuration\nmatch checks, making them match too easily. In particular options related to\nthe private key." }, "properties": { "precision": "very-high", "security-severity": "8.0", "tags": [ "vulnerability", "security", "HIGH" ] } }, { "id": "CVE-2026-9079", "name": "OsPackageVulnerability", "shortDescription": { "text": "libcurl: libcurl: Information disclosure due to failure to clear proxy authentication credentials" }, "fullDescription": { "text": "libcurl had a flaw that when instructed to clear proxy authentication\ncredentials which made it not do so, leaving the old credentials around to get\nused for subsequent transfers that should not know nor use them." }, "defaultConfiguration": { "level": "error" }, "helpUri": "https://avd.aquasec.com/nvd/cve-2026-9079", "help": { "text": "Vulnerability CVE-2026-9079\nSeverity: HIGH\nPackage: libcurl4t64\nFixed Version: \nLink: [CVE-2026-9079](https://avd.aquasec.com/nvd/cve-2026-9079)\nlibcurl had a flaw that when instructed to clear proxy authentication\ncredentials which made it not do so, leaving the old credentials around to get\nused for subsequent transfers that should not know nor use them.", "markdown": "**Vulnerability CVE-2026-9079**\n| Severity | Package | Fixed Version | Link |\n| --- | --- | --- | --- |\n|HIGH|libcurl4t64||[CVE-2026-9079](https://avd.aquasec.com/nvd/cve-2026-9079)|\n\nlibcurl had a flaw that when instructed to clear proxy authentication\ncredentials which made it not do so, leaving the old credentials around to get\nused for subsequent transfers that should not know nor use them." }, "properties": { "precision": "very-high", "security-severity": "8.0", "tags": [ "vulnerability", "security", "HIGH" ] } }, { "id": "CVE-2026-9080", "name": "OsPackageVulnerability", "shortDescription": { "text": "libcurl: libcurl: Use-after-free via curl_easy_pause() in CURLMOPT_SOCKETFUNCTION callback" }, "fullDescription": { "text": "Calling `curl_easy_pause()` within the event-based `CURLMOPT_SOCKETFUNCTION`\ncallback triggers a use-after-free vulnerability, where libcurl attempts to\nstore a flag using a dangling struct pointer immediately after that pointer's\nmemory has been freed." }, "defaultConfiguration": { "level": "error" }, "helpUri": "https://avd.aquasec.com/nvd/cve-2026-9080", "help": { "text": "Vulnerability CVE-2026-9080\nSeverity: HIGH\nPackage: libcurl4t64\nFixed Version: \nLink: [CVE-2026-9080](https://avd.aquasec.com/nvd/cve-2026-9080)\nCalling `curl_easy_pause()` within the event-based `CURLMOPT_SOCKETFUNCTION`\ncallback triggers a use-after-free vulnerability, where libcurl attempts to\nstore a flag using a dangling struct pointer immediately after that pointer's\nmemory has been freed.", "markdown": "**Vulnerability CVE-2026-9080**\n| Severity | Package | Fixed Version | Link |\n| --- | --- | --- | --- |\n|HIGH|libcurl4t64||[CVE-2026-9080](https://avd.aquasec.com/nvd/cve-2026-9080)|\n\nCalling `curl_easy_pause()` within the event-based `CURLMOPT_SOCKETFUNCTION`\ncallback triggers a use-after-free vulnerability, where libcurl attempts to\nstore a flag using a dangling struct pointer immediately after that pointer's\nmemory has been freed." }, "properties": { "precision": "very-high", "security-severity": "8.0", "tags": [ "vulnerability", "security", "HIGH" ] } }, { "id": "CVE-2026-9545", "name": "OsPackageVulnerability", "shortDescription": { "text": "libcurl: libcurl: Information disclosure via cached SSL session and early data" }, "fullDescription": { "text": "In this scenario, libcurl first uses a proper HTTP/3 server for the initial\ntransfers, and when it makes a second transfer to the same site it has been\nreplaced by the attacker's impostor machine - without a valid certificate.\n\nWhen libcurl returns to the hostname the second time with a cached SSL session\n(`CURLOPT_SSL_SESSIONID_CACHE` is not disabled) and early data enabled (the\n`CURLSSLOPT_EARLYDATA` bit is set in `CURLOPT_SSL_OPTIONS`), libcurl might\nsend off the second request's bytes on that new connection *before* enforcing\nthe certificate verification failure. Potentially leaking sensitive\ninformation." }, "defaultConfiguration": { "level": "error" }, "helpUri": "https://avd.aquasec.com/nvd/cve-2026-9545", "help": { "text": "Vulnerability CVE-2026-9545\nSeverity: HIGH\nPackage: libcurl4t64\nFixed Version: \nLink: [CVE-2026-9545](https://avd.aquasec.com/nvd/cve-2026-9545)\nIn this scenario, libcurl first uses a proper HTTP/3 server for the initial\ntransfers, and when it makes a second transfer to the same site it has been\nreplaced by the attacker's impostor machine - without a valid certificate.\n\nWhen libcurl returns to the hostname the second time with a cached SSL session\n(`CURLOPT_SSL_SESSIONID_CACHE` is not disabled) and early data enabled (the\n`CURLSSLOPT_EARLYDATA` bit is set in `CURLOPT_SSL_OPTIONS`), libcurl might\nsend off the second request's bytes on that new connection *before* enforcing\nthe certificate verification failure. Potentially leaking sensitive\ninformation.", "markdown": "**Vulnerability CVE-2026-9545**\n| Severity | Package | Fixed Version | Link |\n| --- | --- | --- | --- |\n|HIGH|libcurl4t64||[CVE-2026-9545](https://avd.aquasec.com/nvd/cve-2026-9545)|\n\nIn this scenario, libcurl first uses a proper HTTP/3 server for the initial\ntransfers, and when it makes a second transfer to the same site it has been\nreplaced by the attacker's impostor machine - without a valid certificate.\n\nWhen libcurl returns to the hostname the second time with a cached SSL session\n(`CURLOPT_SSL_SESSIONID_CACHE` is not disabled) and early data enabled (the\n`CURLSSLOPT_EARLYDATA` bit is set in `CURLOPT_SSL_OPTIONS`), libcurl might\nsend off the second request's bytes on that new connection *before* enforcing\nthe certificate verification failure. Potentially leaking sensitive\ninformation." }, "properties": { "precision": "very-high", "security-severity": "8.0", "tags": [ "vulnerability", "security", "HIGH" ] } }, { "id": "CVE-2026-41992", "name": "OsPackageVulnerability", "shortDescription": { "text": "GNU gzip contains a global buffer overflow vulnerability in the LZH de ..." }, "fullDescription": { "text": "GNU gzip contains a global buffer overflow vulnerability in the LZH decompression logic caused by improper reuse of shared global state between different decompression formats within a single execution. GNU gzip maintains a global array that is shared across the LZ77, LZW, and LZH decompression routines and is not reinitialized between files processed in the same invocation.\nBy decompressing a specially crafted LZW file followed by a specially crafted LZH file in a single gzip -d command, an attacker can poison the shared global state and subsequently trigger an out‑of‑bounds read in the LZH decoder. The LZH decompression logic follows stale values left in the shared array, causing reads past the end of the allocated global buffer.\n\nThis issue has been fixed in the commit 63dbf6b3b9e6e781df1a6a64e609b10e23969681" }, "defaultConfiguration": { "level": "error" }, "helpUri": "https://avd.aquasec.com/nvd/cve-2026-41992", "help": { "text": "Vulnerability CVE-2026-41992\nSeverity: HIGH\nPackage: gzip\nFixed Version: \nLink: [CVE-2026-41992](https://avd.aquasec.com/nvd/cve-2026-41992)\nGNU gzip contains a global buffer overflow vulnerability in the LZH decompression logic caused by improper reuse of shared global state between different decompression formats within a single execution. GNU gzip maintains a global array that is shared across the LZ77, LZW, and LZH decompression routines and is not reinitialized between files processed in the same invocation.\nBy decompressing a specially crafted LZW file followed by a specially crafted LZH file in a single gzip -d command, an attacker can poison the shared global state and subsequently trigger an out‑of‑bounds read in the LZH decoder. The LZH decompression logic follows stale values left in the shared array, causing reads past the end of the allocated global buffer.\n\nThis issue has been fixed in the commit 63dbf6b3b9e6e781df1a6a64e609b10e23969681", "markdown": "**Vulnerability CVE-2026-41992**\n| Severity | Package | Fixed Version | Link |\n| --- | --- | --- | --- |\n|HIGH|gzip||[CVE-2026-41992](https://avd.aquasec.com/nvd/cve-2026-41992)|\n\nGNU gzip contains a global buffer overflow vulnerability in the LZH decompression logic caused by improper reuse of shared global state between different decompression formats within a single execution. GNU gzip maintains a global array that is shared across the LZ77, LZW, and LZH decompression routines and is not reinitialized between files processed in the same invocation.\nBy decompressing a specially crafted LZW file followed by a specially crafted LZH file in a single gzip -d command, an attacker can poison the shared global state and subsequently trigger an out‑of‑bounds read in the LZH decoder. The LZH decompression logic follows stale values left in the shared array, causing reads past the end of the allocated global buffer.\n\nThis issue has been fixed in the commit 63dbf6b3b9e6e781df1a6a64e609b10e23969681" }, "properties": { "cvssv3_baseScore": 7.5, "cvssv3_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", "precision": "very-high", "security-severity": "7.5", "tags": [ "vulnerability", "security", "HIGH" ] } }, { "id": "CVE-2026-54369", "name": "OsPackageVulnerability", "shortDescription": { "text": "acl: Symlink traversal privilege escalation via libacl functions" }, "fullDescription": { "text": "acl before version 2.4.0 contains a symlink traversal vulnerability in the libacl pathname-based functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() that allows local attackers to escalate privileges by replacing any pathname component with a symbolic link. Attackers who control any component of a pathname processed by a privileged caller can redirect ACL read or write operations to arbitrary files or directories, enabling unauthorized manipulation of access control lists and local privilege escalation." }, "defaultConfiguration": { "level": "error" }, "helpUri": "https://avd.aquasec.com/nvd/cve-2026-54369", "help": { "text": "Vulnerability CVE-2026-54369\nSeverity: HIGH\nPackage: libacl1\nFixed Version: \nLink: [CVE-2026-54369](https://avd.aquasec.com/nvd/cve-2026-54369)\nacl before version 2.4.0 contains a symlink traversal vulnerability in the libacl pathname-based functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() that allows local attackers to escalate privileges by replacing any pathname component with a symbolic link. Attackers who control any component of a pathname processed by a privileged caller can redirect ACL read or write operations to arbitrary files or directories, enabling unauthorized manipulation of access control lists and local privilege escalation.", "markdown": "**Vulnerability CVE-2026-54369**\n| Severity | Package | Fixed Version | Link |\n| --- | --- | --- | --- |\n|HIGH|libacl1||[CVE-2026-54369](https://avd.aquasec.com/nvd/cve-2026-54369)|\n\nacl before version 2.4.0 contains a symlink traversal vulnerability in the libacl pathname-based functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() that allows local attackers to escalate privileges by replacing any pathname component with a symbolic link. Attackers who control any component of a pathname processed by a privileged caller can redirect ACL read or write operations to arbitrary files or directories, enabling unauthorized manipulation of access control lists and local privilege escalation." }, "properties": { "precision": "very-high", "security-severity": "8.0", "tags": [ "vulnerability", "security", "HIGH" ] } }, { "id": "CVE-2025-69720", "name": "OsPackageVulnerability", "shortDescription": { "text": "ncurses: ncurses: Buffer overflow vulnerability may lead to arbitrary code execution." }, "fullDescription": { "text": "The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c." }, "defaultConfiguration": { "level": "error" }, "helpUri": "https://avd.aquasec.com/nvd/cve-2025-69720", "help": { "text": "Vulnerability CVE-2025-69720\nSeverity: HIGH\nPackage: ncurses-bin\nFixed Version: \nLink: [CVE-2025-69720](https://avd.aquasec.com/nvd/cve-2025-69720)\nThe infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c.", "markdown": "**Vulnerability CVE-2025-69720**\n| Severity | Package | Fixed Version | Link |\n| --- | --- | --- | --- |\n|HIGH|ncurses-bin||[CVE-2025-69720](https://avd.aquasec.com/nvd/cve-2025-69720)|\n\nThe infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c." }, "properties": { "cvssv3_baseScore": 7.8, "cvssv3_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "precision": "very-high", "security-severity": "7.8", "tags": [ "vulnerability", "security", "HIGH" ] } }, { "id": "CVE-2026-13221", "name": "OsPackageVulnerability", "shortDescription": { "text": "Perl versions through 5.43.9 produce silently incorrect regular expres ..." }, "fullDescription": { "text": "Perl versions through 5.43.9 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie in Perl_study_chunk.\n\nWhen such branches are combined into a trie, the delta between the first branch and the shared tail is stored in a 16-bit field. A branch count above 65535 overflows the field, and the trie's match decision table is truncated with no warning or error.\n\nA pattern of this shape produces false positive matches (matching strings it should not) and false negative matches (failing to match strings it should). When such a pattern gates an access or filtering decision, the result is wrong." }, "defaultConfiguration": { "level": "error" }, "helpUri": "https://avd.aquasec.com/nvd/cve-2026-13221", "help": { "text": "Vulnerability CVE-2026-13221\nSeverity: CRITICAL\nPackage: perl-base\nFixed Version: \nLink: [CVE-2026-13221](https://avd.aquasec.com/nvd/cve-2026-13221)\nPerl versions through 5.43.9 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie in Perl_study_chunk.\n\nWhen such branches are combined into a trie, the delta between the first branch and the shared tail is stored in a 16-bit field. A branch count above 65535 overflows the field, and the trie's match decision table is truncated with no warning or error.\n\nA pattern of this shape produces false positive matches (matching strings it should not) and false negative matches (failing to match strings it should). When such a pattern gates an access or filtering decision, the result is wrong.", "markdown": "**Vulnerability CVE-2026-13221**\n| Severity | Package | Fixed Version | Link |\n| --- | --- | --- | --- |\n|CRITICAL|perl-base||[CVE-2026-13221](https://avd.aquasec.com/nvd/cve-2026-13221)|\n\nPerl versions through 5.43.9 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie in Perl_study_chunk.\n\nWhen such branches are combined into a trie, the delta between the first branch and the shared tail is stored in a 16-bit field. A branch count above 65535 overflows the field, and the trie's match decision table is truncated with no warning or error.\n\nA pattern of this shape produces false positive matches (matching strings it should not) and false negative matches (failing to match strings it should). When such a pattern gates an access or filtering decision, the result is wrong." }, "properties": { "cvssv3_baseScore": 9.1, "cvssv3_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H", "precision": "very-high", "security-severity": "9.1", "tags": [ "vulnerability", "security", "CRITICAL" ] } }, { "id": "CVE-2026-42496", "name": "OsPackageVulnerability", "shortDescription": { "text": "perl-archive-tar: perl-archive-tar: Path traversal via crafted symlinks allows arbitrary file access" }, "fullDescription": { "text": "Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory.\n\n_make_special_file() passes the tar header's linkname to symlink() without validating it against absolute paths or .. segments. The secure-extract mode check that guards regular file extraction does not cover the symlink target.\n\nA subsequent open through the extracted name reads or writes the attacker chosen path." }, "defaultConfiguration": { "level": "error" }, "helpUri": "https://avd.aquasec.com/nvd/cve-2026-42496", "help": { "text": "Vulnerability CVE-2026-42496\nSeverity: CRITICAL\nPackage: perl-base\nFixed Version: \nLink: [CVE-2026-42496](https://avd.aquasec.com/nvd/cve-2026-42496)\nArchive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory.\n\n_make_special_file() passes the tar header's linkname to symlink() without validating it against absolute paths or .. segments. The secure-extract mode check that guards regular file extraction does not cover the symlink target.\n\nA subsequent open through the extracted name reads or writes the attacker chosen path.", "markdown": "**Vulnerability CVE-2026-42496**\n| Severity | Package | Fixed Version | Link |\n| --- | --- | --- | --- |\n|CRITICAL|perl-base||[CVE-2026-42496](https://avd.aquasec.com/nvd/cve-2026-42496)|\n\nArchive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory.\n\n_make_special_file() passes the tar header's linkname to symlink() without validating it against absolute paths or .. segments. The secure-extract mode check that guards regular file extraction does not cover the symlink target.\n\nA subsequent open through the extracted name reads or writes the attacker chosen path." }, "properties": { "cvssv3_baseScore": 9.1, "cvssv3_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N", "precision": "very-high", "security-severity": "9.1", "tags": [ "vulnerability", "security", "CRITICAL" ] } }, { "id": "CVE-2026-57433", "name": "OsPackageVulnerability", "shortDescription": { "text": "Storable versions before 3.41 for Perl have a signed integer overflow ..." }, "fullDescription": { "text": "Storable versions before 3.41 for Perl have a signed integer overflow when deserializing a crafted SX_HOOK record.\n\nretrieve_hook_common reads a signed 32-bit item count from an SX_HOOK record and calls av_extend with that count plus one. A count of I32_MAX wraps the addition to a negative value.\n\nA crafted blob passed to thaw or retrieve triggers the overflow; av_extend receives the negative count and dies with a panic, terminating the deserialization." }, "defaultConfiguration": { "level": "error" }, "helpUri": "https://avd.aquasec.com/nvd/cve-2026-57433", "help": { "text": "Vulnerability CVE-2026-57433\nSeverity: CRITICAL\nPackage: perl-base\nFixed Version: \nLink: [CVE-2026-57433](https://avd.aquasec.com/nvd/cve-2026-57433)\nStorable versions before 3.41 for Perl have a signed integer overflow when deserializing a crafted SX_HOOK record.\n\nretrieve_hook_common reads a signed 32-bit item count from an SX_HOOK record and calls av_extend with that count plus one. A count of I32_MAX wraps the addition to a negative value.\n\nA crafted blob passed to thaw or retrieve triggers the overflow; av_extend receives the negative count and dies with a panic, terminating the deserialization.", "markdown": "**Vulnerability CVE-2026-57433**\n| Severity | Package | Fixed Version | Link |\n| --- | --- | --- | --- |\n|CRITICAL|perl-base||[CVE-2026-57433](https://avd.aquasec.com/nvd/cve-2026-57433)|\n\nStorable versions before 3.41 for Perl have a signed integer overflow when deserializing a crafted SX_HOOK record.\n\nretrieve_hook_common reads a signed 32-bit item count from an SX_HOOK record and calls av_extend with that count plus one. A count of I32_MAX wraps the addition to a negative value.\n\nA crafted blob passed to thaw or retrieve triggers the overflow; av_extend receives the negative count and dies with a panic, terminating the deserialization." }, "properties": { "precision": "very-high", "security-severity": "9.5", "tags": [ "vulnerability", "security", "CRITICAL" ] } }, { "id": "CVE-2026-8376", "name": "OsPackageVulnerability", "shortDescription": { "text": "perl: Perl: Heap buffer overflow when compiling regular expressions on 32-bit builds" }, "fullDescription": { "text": "Perl versions through 5.43.10 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds.\n\nPerl_study_chunk in regcomp_study.c checked the size of the joined substring buffer in characters rather than bytes. For a quantified fixed substring with a large minimum count, the byte length mincount * l could overflow SSize_t, producing an undersized SvGROW allocation; the subsequent copy writes past the end of the buffer.\n\nA caller that compiles an attacker-controlled regular expression on a 32-bit perl build triggers a heap buffer overflow at compile time." }, "defaultConfiguration": { "level": "error" }, "helpUri": "https://avd.aquasec.com/nvd/cve-2026-8376", "help": { "text": "Vulnerability CVE-2026-8376\nSeverity: CRITICAL\nPackage: perl-base\nFixed Version: \nLink: [CVE-2026-8376](https://avd.aquasec.com/nvd/cve-2026-8376)\nPerl versions through 5.43.10 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds.\n\nPerl_study_chunk in regcomp_study.c checked the size of the joined substring buffer in characters rather than bytes. For a quantified fixed substring with a large minimum count, the byte length mincount * l could overflow SSize_t, producing an undersized SvGROW allocation; the subsequent copy writes past the end of the buffer.\n\nA caller that compiles an attacker-controlled regular expression on a 32-bit perl build triggers a heap buffer overflow at compile time.", "markdown": "**Vulnerability CVE-2026-8376**\n| Severity | Package | Fixed Version | Link |\n| --- | --- | --- | --- |\n|CRITICAL|perl-base||[CVE-2026-8376](https://avd.aquasec.com/nvd/cve-2026-8376)|\n\nPerl versions through 5.43.10 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds.\n\nPerl_study_chunk in regcomp_study.c checked the size of the joined substring buffer in characters rather than bytes. For a quantified fixed substring with a large minimum count, the byte length mincount * l could overflow SSize_t, producing an undersized SvGROW allocation; the subsequent copy writes past the end of the buffer.\n\nA caller that compiles an attacker-controlled regular expression on a 32-bit perl build triggers a heap buffer overflow at compile time." }, "properties": { "cvssv3_baseScore": 9.8, "cvssv3_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "precision": "very-high", "security-severity": "9.8", "tags": [ "vulnerability", "security", "CRITICAL" ] } }, { "id": "CVE-2026-42497", "name": "OsPackageVulnerability", "shortDescription": { "text": "perl-Archive-Tar: perl-Archive-Tar: Arbitrary file modification via crafted hardlinks during archive extraction" }, "fullDescription": { "text": "Archive::Tar versions before 3.08 for Perl extract hardlinks to attacker controlled paths outside the extraction directory.\n\n_make_special_file() passes the tar header's linkname to link() without validating it against absolute paths or .. segments, creating a hardlink that shares the victim file's inode.\n\nA subsequent write through the extracted name modifies the victim file, and the post-extraction chmod, chown, and utime block in _extract_file() (guarded only against symlinks via -l) applies the tar header's mode, owner, and timestamps to the shared inode during extraction alone." }, "defaultConfiguration": { "level": "error" }, "helpUri": "https://avd.aquasec.com/nvd/cve-2026-42497", "help": { "text": "Vulnerability CVE-2026-42497\nSeverity: HIGH\nPackage: perl-base\nFixed Version: \nLink: [CVE-2026-42497](https://avd.aquasec.com/nvd/cve-2026-42497)\nArchive::Tar versions before 3.08 for Perl extract hardlinks to attacker controlled paths outside the extraction directory.\n\n_make_special_file() passes the tar header's linkname to link() without validating it against absolute paths or .. segments, creating a hardlink that shares the victim file's inode.\n\nA subsequent write through the extracted name modifies the victim file, and the post-extraction chmod, chown, and utime block in _extract_file() (guarded only against symlinks via -l) applies the tar header's mode, owner, and timestamps to the shared inode during extraction alone.", "markdown": "**Vulnerability CVE-2026-42497**\n| Severity | Package | Fixed Version | Link |\n| --- | --- | --- | --- |\n|HIGH|perl-base||[CVE-2026-42497](https://avd.aquasec.com/nvd/cve-2026-42497)|\n\nArchive::Tar versions before 3.08 for Perl extract hardlinks to attacker controlled paths outside the extraction directory.\n\n_make_special_file() passes the tar header's linkname to link() without validating it against absolute paths or .. segments, creating a hardlink that shares the victim file's inode.\n\nA subsequent write through the extracted name modifies the victim file, and the post-extraction chmod, chown, and utime block in _extract_file() (guarded only against symlinks via -l) applies the tar header's mode, owner, and timestamps to the shared inode during extraction alone." }, "properties": { "cvssv3_baseScore": 7.5, "cvssv3_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N", "precision": "very-high", "security-severity": "7.5", "tags": [ "vulnerability", "security", "HIGH" ] } }, { "id": "CVE-2026-48962", "name": "OsPackageVulnerability", "shortDescription": { "text": "perl-IO-Compress: perl-IO-Compress: Arbitrary code execution via attacker-controlled output glob" }, "fullDescription": { "text": "IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob.\n\n_parseOutputGlob() wraps the caller-supplied output glob string in double quotes and stores it in the parser state; _getFiles() then runs the stored expression through eval STRING. A literal double quote in the output glob closes the dquote wrapper, and the characters that follow are evaluated as Perl.\n\nArbitrary Perl in the output glob executes at the calling process's privilege." }, "defaultConfiguration": { "level": "error" }, "helpUri": "https://avd.aquasec.com/nvd/cve-2026-48962", "help": { "text": "Vulnerability CVE-2026-48962\nSeverity: HIGH\nPackage: perl-base\nFixed Version: \nLink: [CVE-2026-48962](https://avd.aquasec.com/nvd/cve-2026-48962)\nIO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob.\n\n_parseOutputGlob() wraps the caller-supplied output glob string in double quotes and stores it in the parser state; _getFiles() then runs the stored expression through eval STRING. A literal double quote in the output glob closes the dquote wrapper, and the characters that follow are evaluated as Perl.\n\nArbitrary Perl in the output glob executes at the calling process's privilege.", "markdown": "**Vulnerability CVE-2026-48962**\n| Severity | Package | Fixed Version | Link |\n| --- | --- | --- | --- |\n|HIGH|perl-base||[CVE-2026-48962](https://avd.aquasec.com/nvd/cve-2026-48962)|\n\nIO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob.\n\n_parseOutputGlob() wraps the caller-supplied output glob string in double quotes and stores it in the parser state; _getFiles() then runs the stored expression through eval STRING. A literal double quote in the output glob closes the dquote wrapper, and the characters that follow are evaluated as Perl.\n\nArbitrary Perl in the output glob executes at the calling process's privilege." }, "properties": { "precision": "very-high", "security-severity": "8.0", "tags": [ "vulnerability", "security", "HIGH" ] } }, { "id": "CVE-2026-57432", "name": "OsPackageVulnerability", "shortDescription": { "text": "Perl versions through 5.43.10 have an integer overflow in S_measure_st ..." }, "fullDescription": { "text": "Perl versions through 5.43.10 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack.\n\nS_measure_struct adds each item's size times its repeat count to a running total with no overflow check, so a large repeat count in a pack or unpack template wraps the signed SSize_t total negative. The @, X, and x position codes then guard their moves with a signed length comparison that passes when the length is negative, advancing the buffer pointer out of bounds.\n\nA template derived from untrusted input can read heap memory past the buffer and return it to the caller." }, "defaultConfiguration": { "level": "error" }, "helpUri": "https://avd.aquasec.com/nvd/cve-2026-57432", "help": { "text": "Vulnerability CVE-2026-57432\nSeverity: HIGH\nPackage: perl-base\nFixed Version: \nLink: [CVE-2026-57432](https://avd.aquasec.com/nvd/cve-2026-57432)\nPerl versions through 5.43.10 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack.\n\nS_measure_struct adds each item's size times its repeat count to a running total with no overflow check, so a large repeat count in a pack or unpack template wraps the signed SSize_t total negative. The @, X, and x position codes then guard their moves with a signed length comparison that passes when the length is negative, advancing the buffer pointer out of bounds.\n\nA template derived from untrusted input can read heap memory past the buffer and return it to the caller.", "markdown": "**Vulnerability CVE-2026-57432**\n| Severity | Package | Fixed Version | Link |\n| --- | --- | --- | --- |\n|HIGH|perl-base||[CVE-2026-57432](https://avd.aquasec.com/nvd/cve-2026-57432)|\n\nPerl versions through 5.43.10 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack.\n\nS_measure_struct adds each item's size times its repeat count to a running total with no overflow check, so a large repeat count in a pack or unpack template wraps the signed SSize_t total negative. The @, X, and x position codes then guard their moves with a signed length comparison that passes when the length is negative, advancing the buffer pointer out of bounds.\n\nA template derived from untrusted input can read heap memory past the buffer and return it to the caller." }, "properties": { "cvssv3_baseScore": 8.4, "cvssv3_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "precision": "very-high", "security-severity": "8.4", "tags": [ "vulnerability", "security", "HIGH" ] } }, { "id": "CVE-2026-9538", "name": "OsPackageVulnerability", "shortDescription": { "text": "perl-Archive-Tar: perl-Archive-Tar: Denial of Service via crafted tar header with large entry size" }, "fullDescription": { "text": "Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker controlled entry size field in tar header.\n\n_read_tar() reads each entry's payload with $handle-\u003eread($$data, $block), where $block is derived from the entry's 12-byte size field in the tar header with no upper bound on that value.\n\nA crafted header declaring a multi-gigabyte size causes Perl to allocate a scalar of that size." }, "defaultConfiguration": { "level": "error" }, "helpUri": "https://avd.aquasec.com/nvd/cve-2026-9538", "help": { "text": "Vulnerability CVE-2026-9538\nSeverity: HIGH\nPackage: perl-base\nFixed Version: \nLink: [CVE-2026-9538](https://avd.aquasec.com/nvd/cve-2026-9538)\nArchive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker controlled entry size field in tar header.\n\n_read_tar() reads each entry's payload with $handle-\u003eread($$data, $block), where $block is derived from the entry's 12-byte size field in the tar header with no upper bound on that value.\n\nA crafted header declaring a multi-gigabyte size causes Perl to allocate a scalar of that size.", "markdown": "**Vulnerability CVE-2026-9538**\n| Severity | Package | Fixed Version | Link |\n| --- | --- | --- | --- |\n|HIGH|perl-base||[CVE-2026-9538](https://avd.aquasec.com/nvd/cve-2026-9538)|\n\nArchive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker controlled entry size field in tar header.\n\n_read_tar() reads each entry's payload with $handle-\u003eread($$data, $block), where $block is derived from the entry's 12-byte size field in the tar header with no upper bound on that value.\n\nA crafted header declaring a multi-gigabyte size causes Perl to allocate a scalar of that size." }, "properties": { "cvssv3_baseScore": 7.5, "cvssv3_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "precision": "very-high", "security-severity": "7.5", "tags": [ "vulnerability", "security", "HIGH" ] } } ], "version": "0.70.0" } }, "results": [ { "ruleId": "CVE-2026-53615", "ruleIndex": 0, "level": "error", "message": { "text": "Package: bsdutils\nInstalled Version: 1:2.41-5\nVulnerability CVE-2026-53615\nSeverity: HIGH\nFixed Version: \nLink: [CVE-2026-53615](https://avd.aquasec.com/nvd/cve-2026-53615)" }, "locations": [ { "physicalLocation": { "artifactLocation": { "uri": "subculture-collective/hasanara-api", "uriBaseId": "ROOTPATH" }, "region": { "startLine": 1, "startColumn": 1, "endLine": 1, "endColumn": 1 } }, "message": { "text": "subculture-collective/hasanara-api: bsdutils@1:2.41-5" } } ] }, { "ruleId": "CVE-2026-12064", "ruleIndex": 1, "level": "error", "message": { "text": "Package: curl\nInstalled Version: 8.14.1-2+deb13u4\nVulnerability CVE-2026-12064\nSeverity: HIGH\nFixed Version: \nLink: [CVE-2026-12064](https://avd.aquasec.com/nvd/cve-2026-12064)" }, "locations": [ { "physicalLocation": { "artifactLocation": { "uri": "subculture-collective/hasanara-api", "uriBaseId": "ROOTPATH" }, "region": { "startLine": 1, "startColumn": 1, "endLine": 1, "endColumn": 1 } }, "message": { "text": "subculture-collective/hasanara-api: curl@8.14.1-2+deb13u4" } } ] }, { "ruleId": "CVE-2026-8286", "ruleIndex": 2, "level": "error", "message": { "text": "Package: curl\nInstalled Version: 8.14.1-2+deb13u4\nVulnerability CVE-2026-8286\nSeverity: HIGH\nFixed Version: \nLink: [CVE-2026-8286](https://avd.aquasec.com/nvd/cve-2026-8286)" }, "locations": [ { "physicalLocation": { "artifactLocation": { "uri": "subculture-collective/hasanara-api", "uriBaseId": "ROOTPATH" }, "region": { "startLine": 1, "startColumn": 1, "endLine": 1, "endColumn": 1 } }, "message": { "text": "subculture-collective/hasanara-api: curl@8.14.1-2+deb13u4" } } ] }, { "ruleId": "CVE-2026-8927", "ruleIndex": 3, "level": "error", "message": { "text": "Package: curl\nInstalled Version: 8.14.1-2+deb13u4\nVulnerability CVE-2026-8927\nSeverity: HIGH\nFixed Version: \nLink: [CVE-2026-8927](https://avd.aquasec.com/nvd/cve-2026-8927)" }, "locations": [ { "physicalLocation": { "artifactLocation": { "uri": "subculture-collective/hasanara-api", "uriBaseId": "ROOTPATH" }, "region": { "startLine": 1, "startColumn": 1, "endLine": 1, "endColumn": 1 } }, "message": { "text": "subculture-collective/hasanara-api: curl@8.14.1-2+deb13u4" } } ] }, { "ruleId": "CVE-2026-8932", "ruleIndex": 4, "level": "error", "message": { "text": "Package: curl\nInstalled Version: 8.14.1-2+deb13u4\nVulnerability CVE-2026-8932\nSeverity: HIGH\nFixed Version: \nLink: [CVE-2026-8932](https://avd.aquasec.com/nvd/cve-2026-8932)" }, "locations": [ { "physicalLocation": { "artifactLocation": { "uri": "subculture-collective/hasanara-api", "uriBaseId": "ROOTPATH" }, "region": { "startLine": 1, "startColumn": 1, "endLine": 1, "endColumn": 1 } }, "message": { "text": "subculture-collective/hasanara-api: curl@8.14.1-2+deb13u4" } } ] }, { "ruleId": "CVE-2026-9079", "ruleIndex": 5, "level": "error", "message": { "text": "Package: curl\nInstalled Version: 8.14.1-2+deb13u4\nVulnerability CVE-2026-9079\nSeverity: HIGH\nFixed Version: \nLink: [CVE-2026-9079](https://avd.aquasec.com/nvd/cve-2026-9079)" }, "locations": [ { "physicalLocation": { "artifactLocation": { "uri": "subculture-collective/hasanara-api", "uriBaseId": "ROOTPATH" }, "region": { "startLine": 1, "startColumn": 1, "endLine": 1, "endColumn": 1 } }, "message": { "text": "subculture-collective/hasanara-api: curl@8.14.1-2+deb13u4" } } ] }, { "ruleId": "CVE-2026-9080", "ruleIndex": 6, "level": "error", "message": { "text": "Package: curl\nInstalled Version: 8.14.1-2+deb13u4\nVulnerability CVE-2026-9080\nSeverity: HIGH\nFixed Version: \nLink: [CVE-2026-9080](https://avd.aquasec.com/nvd/cve-2026-9080)" }, "locations": [ { "physicalLocation": { "artifactLocation": { "uri": "subculture-collective/hasanara-api", "uriBaseId": "ROOTPATH" }, "region": { "startLine": 1, "startColumn": 1, "endLine": 1, "endColumn": 1 } }, "message": { "text": "subculture-collective/hasanara-api: curl@8.14.1-2+deb13u4" } } ] }, { "ruleId": "CVE-2026-9545", "ruleIndex": 7, "level": "error", "message": { "text": "Package: curl\nInstalled Version: 8.14.1-2+deb13u4\nVulnerability CVE-2026-9545\nSeverity: HIGH\nFixed Version: \nLink: [CVE-2026-9545](https://avd.aquasec.com/nvd/cve-2026-9545)" }, "locations": [ { "physicalLocation": { "artifactLocation": { "uri": "subculture-collective/hasanara-api", "uriBaseId": "ROOTPATH" }, "region": { "startLine": 1, "startColumn": 1, "endLine": 1, "endColumn": 1 } }, "message": { "text": "subculture-collective/hasanara-api: curl@8.14.1-2+deb13u4" } } ] }, { "ruleId": "CVE-2026-41992", "ruleIndex": 8, "level": "error", "message": { "text": "Package: gzip\nInstalled Version: 1.13-1\nVulnerability CVE-2026-41992\nSeverity: HIGH\nFixed Version: \nLink: [CVE-2026-41992](https://avd.aquasec.com/nvd/cve-2026-41992)" }, "locations": [ { "physicalLocation": { "artifactLocation": { "uri": "subculture-collective/hasanara-api", "uriBaseId": "ROOTPATH" }, "region": { "startLine": 1, "startColumn": 1, "endLine": 1, "endColumn": 1 } }, "message": { "text": "subculture-collective/hasanara-api: gzip@1.13-1" } } ] }, { "ruleId": "CVE-2026-54369", "ruleIndex": 9, "level": "error", "message": { "text": "Package: libacl1\nInstalled Version: 2.3.2-2+b1\nVulnerability CVE-2026-54369\nSeverity: HIGH\nFixed Version: \nLink: [CVE-2026-54369](https://avd.aquasec.com/nvd/cve-2026-54369)" }, "locations": [ { "physicalLocation": { "artifactLocation": { "uri": "subculture-collective/hasanara-api", "uriBaseId": "ROOTPATH" }, "region": { "startLine": 1, "startColumn": 1, "endLine": 1, "endColumn": 1 } }, "message": { "text": "subculture-collective/hasanara-api: libacl1@2.3.2-2+b1" } } ] }, { "ruleId": "CVE-2026-53615", "ruleIndex": 0, "level": "error", "message": { "text": "Package: libblkid1\nInstalled Version: 2.41-5\nVulnerability CVE-2026-53615\nSeverity: HIGH\nFixed Version: \nLink: [CVE-2026-53615](https://avd.aquasec.com/nvd/cve-2026-53615)" }, "locations": [ { "physicalLocation": { "artifactLocation": { "uri": "subculture-collective/hasanara-api", "uriBaseId": "ROOTPATH" }, "region": { "startLine": 1, "startColumn": 1, "endLine": 1, "endColumn": 1 } }, "message": { "text": "subculture-collective/hasanara-api: libblkid1@2.41-5" } } ] }, { "ruleId": "CVE-2026-12064", "ruleIndex": 1, "level": "error", "message": { "text": "Package: libcurl4t64\nInstalled Version: 8.14.1-2+deb13u4\nVulnerability CVE-2026-12064\nSeverity: HIGH\nFixed Version: \nLink: [CVE-2026-12064](https://avd.aquasec.com/nvd/cve-2026-12064)" }, "locations": [ { "physicalLocation": { "artifactLocation": { "uri": "subculture-collective/hasanara-api", "uriBaseId": "ROOTPATH" }, "region": { "startLine": 1, "startColumn": 1, "endLine": 1, "endColumn": 1 } }, "message": { "text": "subculture-collective/hasanara-api: libcurl4t64@8.14.1-2+deb13u4" } } ] }, { "ruleId": "CVE-2026-8286", "ruleIndex": 2, "level": "error", "message": { "text": "Package: libcurl4t64\nInstalled Version: 8.14.1-2+deb13u4\nVulnerability CVE-2026-8286\nSeverity: HIGH\nFixed Version: \nLink: [CVE-2026-8286](https://avd.aquasec.com/nvd/cve-2026-8286)" }, "locations": [ { "physicalLocation": { "artifactLocation": { "uri": "subculture-collective/hasanara-api", "uriBaseId": "ROOTPATH" }, "region": { "startLine": 1, "startColumn": 1, "endLine": 1, "endColumn": 1 } }, "message": { "text": "subculture-collective/hasanara-api: libcurl4t64@8.14.1-2+deb13u4" } } ] }, { "ruleId": "CVE-2026-8927", "ruleIndex": 3, "level": "error", "message": { "text": "Package: libcurl4t64\nInstalled Version: 8.14.1-2+deb13u4\nVulnerability CVE-2026-8927\nSeverity: HIGH\nFixed Version: \nLink: [CVE-2026-8927](https://avd.aquasec.com/nvd/cve-2026-8927)" }, "locations": [ { "physicalLocation": { "artifactLocation": { "uri": "subculture-collective/hasanara-api", "uriBaseId": "ROOTPATH" }, "region": { "startLine": 1, "startColumn": 1, "endLine": 1, "endColumn": 1 } }, "message": { "text": "subculture-collective/hasanara-api: libcurl4t64@8.14.1-2+deb13u4" } } ] }, { "ruleId": "CVE-2026-8932", "ruleIndex": 4, "level": "error", "message": { "text": "Package: libcurl4t64\nInstalled Version: 8.14.1-2+deb13u4\nVulnerability CVE-2026-8932\nSeverity: HIGH\nFixed Version: \nLink: [CVE-2026-8932](https://avd.aquasec.com/nvd/cve-2026-8932)" }, "locations": [ { "physicalLocation": { "artifactLocation": { "uri": "subculture-collective/hasanara-api", "uriBaseId": "ROOTPATH" }, "region": { "startLine": 1, "startColumn": 1, "endLine": 1, "endColumn": 1 } }, "message": { "text": "subculture-collective/hasanara-api: libcurl4t64@8.14.1-2+deb13u4" } } ] }, { "ruleId": "CVE-2026-9079", "ruleIndex": 5, "level": "error", "message": { "text": "Package: libcurl4t64\nInstalled Version: 8.14.1-2+deb13u4\nVulnerability CVE-2026-9079\nSeverity: HIGH\nFixed Version: \nLink: [CVE-2026-9079](https://avd.aquasec.com/nvd/cve-2026-9079)" }, "locations": [ { "physicalLocation": { "artifactLocation": { "uri": "subculture-collective/hasanara-api", "uriBaseId": "ROOTPATH" }, "region": { "startLine": 1, "startColumn": 1, "endLine": 1, "endColumn": 1 } }, "message": { "text": "subculture-collective/hasanara-api: libcurl4t64@8.14.1-2+deb13u4" } } ] }, { "ruleId": "CVE-2026-9080", "ruleIndex": 6, "level": "error", "message": { "text": "Package: libcurl4t64\nInstalled Version: 8.14.1-2+deb13u4\nVulnerability CVE-2026-9080\nSeverity: HIGH\nFixed Version: \nLink: [CVE-2026-9080](https://avd.aquasec.com/nvd/cve-2026-9080)" }, "locations": [ { "physicalLocation": { "artifactLocation": { "uri": "subculture-collective/hasanara-api", "uriBaseId": "ROOTPATH" }, "region": { "startLine": 1, "startColumn": 1, "endLine": 1, "endColumn": 1 } }, "message": { "text": "subculture-collective/hasanara-api: libcurl4t64@8.14.1-2+deb13u4" } } ] }, { "ruleId": "CVE-2026-9545", "ruleIndex": 7, "level": "error", "message": { "text": "Package: libcurl4t64\nInstalled Version: 8.14.1-2+deb13u4\nVulnerability CVE-2026-9545\nSeverity: HIGH\nFixed Version: \nLink: [CVE-2026-9545](https://avd.aquasec.com/nvd/cve-2026-9545)" }, "locations": [ { "physicalLocation": { "artifactLocation": { "uri": "subculture-collective/hasanara-api", "uriBaseId": "ROOTPATH" }, "region": { "startLine": 1, "startColumn": 1, "endLine": 1, "endColumn": 1 } }, "message": { "text": "subculture-collective/hasanara-api: libcurl4t64@8.14.1-2+deb13u4" } } ] }, { "ruleId": "CVE-2026-53615", "ruleIndex": 0, "level": "error", "message": { "text": "Package: liblastlog2-2\nInstalled Version: 2.41-5\nVulnerability CVE-2026-53615\nSeverity: HIGH\nFixed Version: \nLink: [CVE-2026-53615](https://avd.aquasec.com/nvd/cve-2026-53615)" }, "locations": [ { "physicalLocation": { "artifactLocation": { "uri": "subculture-collective/hasanara-api", "uriBaseId": "ROOTPATH" }, "region": { "startLine": 1, "startColumn": 1, "endLine": 1, "endColumn": 1 } }, "message": { "text": "subculture-collective/hasanara-api: liblastlog2-2@2.41-5" } } ] }, { "ruleId": "CVE-2026-53615", "ruleIndex": 0, "level": "error", "message": { "text": "Package: libmount1\nInstalled Version: 2.41-5\nVulnerability CVE-2026-53615\nSeverity: HIGH\nFixed Version: \nLink: [CVE-2026-53615](https://avd.aquasec.com/nvd/cve-2026-53615)" }, "locations": [ { "physicalLocation": { "artifactLocation": { "uri": "subculture-collective/hasanara-api", "uriBaseId": "ROOTPATH" }, "region": { "startLine": 1, "startColumn": 1, "endLine": 1, "endColumn": 1 } }, "message": { "text": "subculture-collective/hasanara-api: libmount1@2.41-5" } } ] }, { "ruleId": "CVE-2025-69720", "ruleIndex": 10, "level": "error", "message": { "text": "Package: libncursesw6\nInstalled Version: 6.5+20250216-2\nVulnerability CVE-2025-69720\nSeverity: HIGH\nFixed Version: \nLink: [CVE-2025-69720](https://avd.aquasec.com/nvd/cve-2025-69720)" }, "locations": [ { "physicalLocation": { "artifactLocation": { "uri": "subculture-collective/hasanara-api", "uriBaseId": "ROOTPATH" }, "region": { "startLine": 1, "startColumn": 1, "endLine": 1, "endColumn": 1 } }, "message": { "text": "subculture-collective/hasanara-api: libncursesw6@6.5+20250216-2" } } ] }, { "ruleId": "CVE-2026-53615", "ruleIndex": 0, "level": "error", "message": { "text": "Package: libsmartcols1\nInstalled Version: 2.41-5\nVulnerability CVE-2026-53615\nSeverity: HIGH\nFixed Version: \nLink: [CVE-2026-53615](https://avd.aquasec.com/nvd/cve-2026-53615)" }, "locations": [ { "physicalLocation": { "artifactLocation": { "uri": "subculture-collective/hasanara-api", "uriBaseId": "ROOTPATH" }, "region": { "startLine": 1, "startColumn": 1, "endLine": 1, "endColumn": 1 } }, "message": { "text": "subculture-collective/hasanara-api: libsmartcols1@2.41-5" } } ] }, { "ruleId": "CVE-2025-69720", "ruleIndex": 10, "level": "error", "message": { "text": "Package: libtinfo6\nInstalled Version: 6.5+20250216-2\nVulnerability CVE-2025-69720\nSeverity: HIGH\nFixed Version: \nLink: [CVE-2025-69720](https://avd.aquasec.com/nvd/cve-2025-69720)" }, "locations": [ { "physicalLocation": { "artifactLocation": { "uri": "subculture-collective/hasanara-api", "uriBaseId": "ROOTPATH" }, "region": { "startLine": 1, "startColumn": 1, "endLine": 1, "endColumn": 1 } }, "message": { "text": "subculture-collective/hasanara-api: libtinfo6@6.5+20250216-2" } } ] }, { "ruleId": "CVE-2026-53615", "ruleIndex": 0, "level": "error", "message": { "text": "Package: libuuid1\nInstalled Version: 2.41-5\nVulnerability CVE-2026-53615\nSeverity: HIGH\nFixed Version: \nLink: [CVE-2026-53615](https://avd.aquasec.com/nvd/cve-2026-53615)" }, "locations": [ { "physicalLocation": { "artifactLocation": { "uri": "subculture-collective/hasanara-api", "uriBaseId": "ROOTPATH" }, "region": { "startLine": 1, "startColumn": 1, "endLine": 1, "endColumn": 1 } }, "message": { "text": "subculture-collective/hasanara-api: libuuid1@2.41-5" } } ] }, { "ruleId": "CVE-2026-53615", "ruleIndex": 0, "level": "error", "message": { "text": "Package: login\nInstalled Version: 1:4.16.0-2+really2.41-5\nVulnerability CVE-2026-53615\nSeverity: HIGH\nFixed Version: \nLink: [CVE-2026-53615](https://avd.aquasec.com/nvd/cve-2026-53615)" }, "locations": [ { "physicalLocation": { "artifactLocation": { "uri": "subculture-collective/hasanara-api", "uriBaseId": "ROOTPATH" }, "region": { "startLine": 1, "startColumn": 1, "endLine": 1, "endColumn": 1 } }, "message": { "text": "subculture-collective/hasanara-api: login@1:4.16.0-2+really2.41-5" } } ] }, { "ruleId": "CVE-2026-53615", "ruleIndex": 0, "level": "error", "message": { "text": "Package: mount\nInstalled Version: 2.41-5\nVulnerability CVE-2026-53615\nSeverity: HIGH\nFixed Version: \nLink: [CVE-2026-53615](https://avd.aquasec.com/nvd/cve-2026-53615)" }, "locations": [ { "physicalLocation": { "artifactLocation": { "uri": "subculture-collective/hasanara-api", "uriBaseId": "ROOTPATH" }, "region": { "startLine": 1, "startColumn": 1, "endLine": 1, "endColumn": 1 } }, "message": { "text": "subculture-collective/hasanara-api: mount@2.41-5" } } ] }, { "ruleId": "CVE-2025-69720", "ruleIndex": 10, "level": "error", "message": { "text": "Package: ncurses-base\nInstalled Version: 6.5+20250216-2\nVulnerability CVE-2025-69720\nSeverity: HIGH\nFixed Version: \nLink: [CVE-2025-69720](https://avd.aquasec.com/nvd/cve-2025-69720)" }, "locations": [ { "physicalLocation": { "artifactLocation": { "uri": "subculture-collective/hasanara-api", "uriBaseId": "ROOTPATH" }, "region": { "startLine": 1, "startColumn": 1, "endLine": 1, "endColumn": 1 } }, "message": { "text": "subculture-collective/hasanara-api: ncurses-base@6.5+20250216-2" } } ] }, { "ruleId": "CVE-2025-69720", "ruleIndex": 10, "level": "error", "message": { "text": "Package: ncurses-bin\nInstalled Version: 6.5+20250216-2\nVulnerability CVE-2025-69720\nSeverity: HIGH\nFixed Version: \nLink: [CVE-2025-69720](https://avd.aquasec.com/nvd/cve-2025-69720)" }, "locations": [ { "physicalLocation": { "artifactLocation": { "uri": "subculture-collective/hasanara-api", "uriBaseId": "ROOTPATH" }, "region": { "startLine": 1, "startColumn": 1, "endLine": 1, "endColumn": 1 } }, "message": { "text": "subculture-collective/hasanara-api: ncurses-bin@6.5+20250216-2" } } ] }, { "ruleId": "CVE-2026-13221", "ruleIndex": 11, "level": "error", "message": { "text": "Package: perl-base\nInstalled Version: 5.40.1-6\nVulnerability CVE-2026-13221\nSeverity: CRITICAL\nFixed Version: \nLink: [CVE-2026-13221](https://avd.aquasec.com/nvd/cve-2026-13221)" }, "locations": [ { "physicalLocation": { "artifactLocation": { "uri": "subculture-collective/hasanara-api", "uriBaseId": "ROOTPATH" }, "region": { "startLine": 1, "startColumn": 1, "endLine": 1, "endColumn": 1 } }, "message": { "text": "subculture-collective/hasanara-api: perl-base@5.40.1-6" } } ] }, { "ruleId": "CVE-2026-42496", "ruleIndex": 12, "level": "error", "message": { "text": "Package: perl-base\nInstalled Version: 5.40.1-6\nVulnerability CVE-2026-42496\nSeverity: CRITICAL\nFixed Version: \nLink: [CVE-2026-42496](https://avd.aquasec.com/nvd/cve-2026-42496)" }, "locations": [ { "physicalLocation": { "artifactLocation": { "uri": "subculture-collective/hasanara-api", "uriBaseId": "ROOTPATH" }, "region": { "startLine": 1, "startColumn": 1, "endLine": 1, "endColumn": 1 } }, "message": { "text": "subculture-collective/hasanara-api: perl-base@5.40.1-6" } } ] }, { "ruleId": "CVE-2026-57433", "ruleIndex": 13, "level": "error", "message": { "text": "Package: perl-base\nInstalled Version: 5.40.1-6\nVulnerability CVE-2026-57433\nSeverity: CRITICAL\nFixed Version: \nLink: [CVE-2026-57433](https://avd.aquasec.com/nvd/cve-2026-57433)" }, "locations": [ { "physicalLocation": { "artifactLocation": { "uri": "subculture-collective/hasanara-api", "uriBaseId": "ROOTPATH" }, "region": { "startLine": 1, "startColumn": 1, "endLine": 1, "endColumn": 1 } }, "message": { "text": "subculture-collective/hasanara-api: perl-base@5.40.1-6" } } ] }, { "ruleId": "CVE-2026-8376", "ruleIndex": 14, "level": "error", "message": { "text": "Package: perl-base\nInstalled Version: 5.40.1-6\nVulnerability CVE-2026-8376\nSeverity: CRITICAL\nFixed Version: \nLink: [CVE-2026-8376](https://avd.aquasec.com/nvd/cve-2026-8376)" }, "locations": [ { "physicalLocation": { "artifactLocation": { "uri": "subculture-collective/hasanara-api", "uriBaseId": "ROOTPATH" }, "region": { "startLine": 1, "startColumn": 1, "endLine": 1, "endColumn": 1 } }, "message": { "text": "subculture-collective/hasanara-api: perl-base@5.40.1-6" } } ] }, { "ruleId": "CVE-2026-42497", "ruleIndex": 15, "level": "error", "message": { "text": "Package: perl-base\nInstalled Version: 5.40.1-6\nVulnerability CVE-2026-42497\nSeverity: HIGH\nFixed Version: \nLink: [CVE-2026-42497](https://avd.aquasec.com/nvd/cve-2026-42497)" }, "locations": [ { "physicalLocation": { "artifactLocation": { "uri": "subculture-collective/hasanara-api", "uriBaseId": "ROOTPATH" }, "region": { "startLine": 1, "startColumn": 1, "endLine": 1, "endColumn": 1 } }, "message": { "text": "subculture-collective/hasanara-api: perl-base@5.40.1-6" } } ] }, { "ruleId": "CVE-2026-48962", "ruleIndex": 16, "level": "error", "message": { "text": "Package: perl-base\nInstalled Version: 5.40.1-6\nVulnerability CVE-2026-48962\nSeverity: HIGH\nFixed Version: \nLink: [CVE-2026-48962](https://avd.aquasec.com/nvd/cve-2026-48962)" }, "locations": [ { "physicalLocation": { "artifactLocation": { "uri": "subculture-collective/hasanara-api", "uriBaseId": "ROOTPATH" }, "region": { "startLine": 1, "startColumn": 1, "endLine": 1, "endColumn": 1 } }, "message": { "text": "subculture-collective/hasanara-api: perl-base@5.40.1-6" } } ] }, { "ruleId": "CVE-2026-57432", "ruleIndex": 17, "level": "error", "message": { "text": "Package: perl-base\nInstalled Version: 5.40.1-6\nVulnerability CVE-2026-57432\nSeverity: HIGH\nFixed Version: \nLink: [CVE-2026-57432](https://avd.aquasec.com/nvd/cve-2026-57432)" }, "locations": [ { "physicalLocation": { "artifactLocation": { "uri": "subculture-collective/hasanara-api", "uriBaseId": "ROOTPATH" }, "region": { "startLine": 1, "startColumn": 1, "endLine": 1, "endColumn": 1 } }, "message": { "text": "subculture-collective/hasanara-api: perl-base@5.40.1-6" } } ] }, { "ruleId": "CVE-2026-9538", "ruleIndex": 18, "level": "error", "message": { "text": "Package: perl-base\nInstalled Version: 5.40.1-6\nVulnerability CVE-2026-9538\nSeverity: HIGH\nFixed Version: \nLink: [CVE-2026-9538](https://avd.aquasec.com/nvd/cve-2026-9538)" }, "locations": [ { "physicalLocation": { "artifactLocation": { "uri": "subculture-collective/hasanara-api", "uriBaseId": "ROOTPATH" }, "region": { "startLine": 1, "startColumn": 1, "endLine": 1, "endColumn": 1 } }, "message": { "text": "subculture-collective/hasanara-api: perl-base@5.40.1-6" } } ] }, { "ruleId": "CVE-2026-53615", "ruleIndex": 0, "level": "error", "message": { "text": "Package: util-linux\nInstalled Version: 2.41-5\nVulnerability CVE-2026-53615\nSeverity: HIGH\nFixed Version: \nLink: [CVE-2026-53615](https://avd.aquasec.com/nvd/cve-2026-53615)" }, "locations": [ { "physicalLocation": { "artifactLocation": { "uri": "subculture-collective/hasanara-api", "uriBaseId": "ROOTPATH" }, "region": { "startLine": 1, "startColumn": 1, "endLine": 1, "endColumn": 1 } }, "message": { "text": "subculture-collective/hasanara-api: util-linux@2.41-5" } } ] } ], "columnKind": "utf16CodeUnits", "properties": { "imageID": "sha256:414ad4d00a471e71824adb75cb404d75918d7ee3c825d712f536136e1edf3331", "imageName": "git.subcult.tv/subculture-collective/hasanara-api@sha256:4b56ef9c1ecb1fbf5c369e315096dd60cf615a8124fba8ede6b7d025936077bc", "repoDigests": [ "git.subcult.tv/subculture-collective/hasanara-api@sha256:4b56ef9c1ecb1fbf5c369e315096dd60cf615a8124fba8ede6b7d025936077bc" ], "repoTags": [] } } ] }