add records for CVE's in release 5.9.4 - #31
JacobBarthelmeh wants to merge 2 commits into
Conversation
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
The missing 5.9.4 release catalogue prevents CI from generating and publishing the release bundle.
Review effort: Balanced
Findings: 1
What changed in this PR
Adds 11 wolfSSL 5.9.4 CVE records and corresponding VEX metadata.
Changes:
- Adds canonical CVE records, affected ranges, CVSS scores, and references.
- Marks vulnerabilities fixed in 5.9.4 with remediation and build constraints.
| File | Description |
|---|---|
advisories/vex-overlay.json |
Adds VEX metadata for all 11 CVEs. |
advisories/records/CVE-2026-94419.json |
Adds session-cache poisoning record. |
advisories/records/CVE-2026-94418.json |
Adds signature-verification record. |
advisories/records/CVE-2026-94417.json |
Adds OCSP/CRL bypass record. |
advisories/records/CVE-2026-93304.json |
Adds early ChangeCipherSpec record. |
advisories/records/CVE-2026-93302.json |
Adds trusted-peer validation record. |
advisories/records/CVE-2026-89136.json |
Adds unsolicited RPK record. |
advisories/records/CVE-2026-89135.json |
Adds CertManager poisoning record. |
advisories/records/CVE-2026-89134.json |
Adds Subject CN constraint record. |
advisories/records/CVE-2026-89133.json |
Adds NameConstraints record. |
advisories/records/CVE-2026-89102.json |
Adds OCSP stapling v2 record. |
advisories/records/CVE-2026-15442.json |
Adds shutdown use-after-free record. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
|
Leave advisories/out/ and advisories/publish/ out of this pull request. Those files are built from the CVE records, the overlay, and the release directory. CI rebuilds them on every pull request and checks the schema, the hashes, and the publish layout. A copy in git can disagree with those sources. The signed files are made at deploy with the gpg key. |
Sounds good, I think they were not checked in, and currently are left out? Let me know though if I missed excluding them and should make some changes to the PR. |

No description provided.